Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version:29-08-2015
Ran by skotn_000 (administrator) on SKOTNICA (30-08-2015 16:05:56)
Running from C:\Users\skotn_000\Desktop
Loaded Profiles: skotn_000 (Available Profiles: skotn_000 & Test)
Platform: Windows 8 (X64) Language: Čeština (Česká republika)
Internet Explorer Version 10 (Default browser: Chrome)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool:
http://www.geekstogo.com/forum/topic/33 ... scan-tool/
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(Qualcomm Atheros Commnucations) C:\Program Files (x86)\Bluetooth Suite\AdminService.exe
(Broadcom Corp.) C:\Program Files\Broadcom\MemoryCard\BrcmCardReader.exe
(Acer Incorporated) C:\Program Files (x86)\Acer\Acer Cloud\CCDMonitorService.exe
(Microsoft Corporation) C:\Program Files\Microsoft Office 15\ClientX64\officeclicktorun.exe
(Dritek System Inc.) C:\Program Files (x86)\Launch Manager\dsiwmis.exe
(ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDService.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe
(Intel(R) Corporation) C:\Program Files\Intel\iCLS Client\HeciServer.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\Jhi_service.exe
(Symantec Corporation) C:\Program Files (x86)\Symantec\Norton Online Backup\NOBuAgent.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamService.exe
() C:\Windows\SysWOW64\PnkBstrA.exe
(Dritek System INC.) C:\Windows\RfBtnSvc64.exe
(Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe
(Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(Nero AG) C:\Program Files (x86)\Nero\Update\NASvc.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
(Acer Incorporated) C:\Program Files\Acer\Acer Power Management\ePowerSvc.exe
(Avast Software) C:\Program Files\AVAST Software\Avast\ng\vbox\AvastVBoxSVC.exe
(Microsoft Corporation) C:\Windows\System32\LogonUI.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDCtrl.exe
(Dritek System Inc.) C:\Program Files (x86)\Launch Manager\LMutilps32.exe
(IvoSoft) C:\Program Files\Classic Shell\ClassicStartMenu.exe
(Dritek System Inc.) C:\Program Files (x86)\Launch Manager\LManager.exe
(Microsoft Corporation) C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_17.0.1114.318_x64__8wekyb3d8bbwe\LiveComm.exe
(Dritek System Inc.) C:\Program Files (x86)\Launch Manager\MMDx64Fx.exe
(Intel Corporation) C:\Windows\System32\igfxext.exe
(ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDCtrlHelper.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamNetworkService.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamUserAgent.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe
(Qualcomm Atheros Commnucations) C:\Program Files (x86)\Bluetooth Suite\BtvStack.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(Intel Corporation) C:\Windows\System32\igfxpers.exe
() C:\Program Files (x86)\Bluetooth Suite\ActivateDesktop.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
(Acer Incorporated) C:\Program Files\Acer\Acer Power Management\ePowerTray.exe
(Dritek System Inc.) C:\Program Files (x86)\RadioController\RfBtnHelper.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastUI.exe
(Intel Corporation) C:\Windows\System32\igfxsrvc.exe
(Acer Incorporated) C:\Program Files\Acer\Acer Power Management\ePowerEvent.exe
(Google Inc.) C:\Users\skotn_000\AppData\Local\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Users\skotn_000\AppData\Local\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Users\skotn_000\AppData\Local\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Users\skotn_000\AppData\Local\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Users\skotn_000\AppData\Local\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Users\skotn_000\AppData\Local\Google\Chrome\Application\chrome.exe
(forum.viry.cz) C:\Users\skotn_000\Desktop\FRSTLauncher.exe
==================== Registry (Whitelisted) ===========================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [ETDCtrl] => C:\Program Files\Elantech\ETDCtrl.exe [2873744 2012-11-20] (ELAN Microelectronics Corp.)
HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [12503184 2012-06-11] (Realtek Semiconductor)
HKLM\...\Run: [Classic Start Menu] => C:\Program Files\Classic Shell\ClassicStartMenu.exe [164112 2015-05-16] (IvoSoft)
HKLM\...\Run: [XMouseButtonControl] => C:\Program Files\Highresolution Enterprises\X-Mouse Button Control\XMouseButtonControl.exe [1091568 2015-03-03] (Highresolution Enterprises)
HKLM\...\Run: [NvBackend] => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe [2634872 2015-08-18] (NVIDIA Corporation)
HKLM\...\Run: [ShadowPlay] => C:\WINDOWS\system32\rundll32.exe C:\WINDOWS\system32\nvspcap64.dll,ShadowPlayOnSystemStart
HKLM-x32\...\Run: [RadioController] => C:\Program Files (x86)\RadioController\RfBtnHelper.exe [111216 2013-07-15] (Dritek System Inc.)
HKLM-x32\...\Run: [Norton Online Backup] => C:\Program Files (x86)\Symantec\Norton Online Backup\NOBuClient.exe [2994880 2012-08-15] (Symantec Corporation)
HKLM-x32\...\Run: [32ndBuzzer] => C:\Program Files (x86)\32nd Regiment Buzzer\Buzzer.exe [180224 2015-01-17] ()
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [334896 2015-04-30] (Oracle Corporation)
HKLM-x32\...\Run: [SDTray] => C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe [4101576 2014-06-24] (Safer-Networking Ltd.)
HKLM-x32\...\Run: [AvastUI.exe] => C:\Program Files\AVAST Software\Avast\AvastUI.exe [6109776 2015-08-29] (AVAST Software)
Winlogon\Notify\igfxcui: C:\WINDOWS\system32\igfxdev.dll (Intel Corporation)
Winlogon\Notify\SDWinLogon-x32: SDWinLogon.dll [X]
HKLM\...\Policies\Explorer\Run: [BtvStack] => C:\Program Files (x86)\Bluetooth Suite\BtvStack.exe [131712 2013-01-25] (Qualcomm Atheros Commnucations)
HKU\S-1-5-21-3338900602-571765566-1102821152-1002\...\Run: [Google Update] => C:\Users\skotn_000\AppData\Local\Google\Update\GoogleUpdate.exe [107848 2015-05-24] (Google Inc.)
HKU\S-1-5-21-3338900602-571765566-1102821152-1002\...\Run: [Steam] => C:\Program Files (x86)\Steam\steam.exe [2899136 2015-08-19] (Valve Corporation)
HKU\S-1-5-21-3338900602-571765566-1102821152-1002\...\Run: [Overwolf] => C:\Program Files (x86)\Overwolf\Overwolf.exe [41200 2015-07-19] (Overwolf LTD)
HKU\S-1-5-21-3338900602-571765566-1102821152-1002\...\Run: [DAEMON Tools Lite Automount] => C:\Program Files\DAEMON Tools Lite\DTAgent.exe [4471536 2015-05-21] (Disc Soft Ltd)
HKU\S-1-5-21-3338900602-571765566-1102821152-1002\...\Run: [CCleaner Monitoring] => C:\Program Files\CCleaner\CCleaner64.exe [8322328 2015-05-08] (Piriform Ltd)
HKU\S-1-5-21-3338900602-571765566-1102821152-1002\...\Run: [Dropbox Update] => C:\Users\skotn_000\AppData\Local\Dropbox\Update\DropboxUpdate.exe [134512 2015-06-22] (Dropbox, Inc.)
HKU\S-1-5-21-3338900602-571765566-1102821152-1002\...\Run: [MK LOL] => C:\Program Files (x86)\MKJogo\MK IM\Bin\MKIM.exe [1092296 2015-07-03] ()
HKU\S-1-5-21-3338900602-571765566-1102821152-1002\...\Run: [Spotify Web Helper] => C:\Users\skotn_000\AppData\Roaming\Spotify\SpotifyWebHelper.exe [2008632 2015-07-14] (Spotify Ltd)
AppInit_DLLs: C:\Windows\system32\nvinitx.dll => C:\Windows\system32\nvinitx.dll [177088 2015-08-07] (NVIDIA Corporation)
AppInit_DLLs: ,C:\WINDOWS\system32\nvinitx.dll => C:\WINDOWS\system32\nvinitx.dll [177088 2015-08-07] (NVIDIA Corporation)
AppInit_DLLs-x32: C:\Windows\SysWOW64\nvinit.dll => C:\Windows\SysWOW64\nvinit.dll [155792 2015-08-07] (NVIDIA Corporation)
AppInit_DLLs-x32: ,C:\WINDOWS\SysWOW64\nvinit.dll => C:\WINDOWS\SysWOW64\nvinit.dll [155792 2015-08-07] (NVIDIA Corporation)
ShellIconOverlayIdentifiers: ["DropboxExt1"] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\skotn_000\AppData\Roaming\Dropbox\bin\DropboxExt64.27.dll [2015-08-06] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: ["DropboxExt2"] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\skotn_000\AppData\Roaming\Dropbox\bin\DropboxExt64.27.dll [2015-08-06] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: ["DropboxExt3"] -> {FB314EDD-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\skotn_000\AppData\Roaming\Dropbox\bin\DropboxExt64.27.dll [2015-08-06] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: ["DropboxExt4"] -> {FB314EDE-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\skotn_000\AppData\Roaming\Dropbox\bin\DropboxExt64.27.dll [2015-08-06] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: ["DropboxExt5"] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\skotn_000\AppData\Roaming\Dropbox\bin\DropboxExt64.27.dll [2015-08-06] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: ["DropboxExt6"] -> {FB314EDF-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\skotn_000\AppData\Roaming\Dropbox\bin\DropboxExt64.27.dll [2015-08-06] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: ["DropboxExt7"] -> {FB314EDC-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\skotn_000\AppData\Roaming\Dropbox\bin\DropboxExt64.27.dll [2015-08-06] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: ["DropboxExt8"] -> {FB314EE0-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\skotn_000\AppData\Roaming\Dropbox\bin\DropboxExt64.27.dll [2015-08-06] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShA64.dll [2015-08-29] (AVAST Software)
ShellIconOverlayIdentifiers: [ShareOverlay] -> {594D4122-1F87-41E2-96C7-825FB4796516} => C:\Program Files\Classic Shell\ClassicExplorer64.dll [2015-05-16] (IvoSoft)
ShellIconOverlayIdentifiers-x32: [ShareOverlay] -> {594D4122-1F87-41E2-96C7-825FB4796516} => C:\Program Files\Classic Shell\ClassicExplorer32.dll [2015-05-16] (IvoSoft)
BootExecute: autocheck autochk * sdnclean64.exe
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
HKU\S-1-5-21-3338900602-571765566-1102821152-1002\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://acer13.msn.com/
HKU\S-1-5-21-3338900602-571765566-1102821152-1002\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://acer13.msn.com
SearchScopes: HKU\S-1-5-21-3338900602-571765566-1102821152-1002 -> DefaultScope {ADFE554B-F9EB-4A6E-8DFF-109E2A19B116} URL =
SearchScopes: HKU\S-1-5-21-3338900602-571765566-1102821152-1002 -> {ADFE554B-F9EB-4A6E-8DFF-109E2A19B116} URL =
BHO: Skype for Business Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX64\Microsoft Office\Office15\OCHelper.dll [2015-07-14] (Microsoft Corporation)
BHO: ExplorerBHO Class -> {449D0D6E-2412-4E61-B68F-1CB625CD9E52} -> C:\Program Files\Classic Shell\ClassicExplorer64.dll [2015-05-16] (IvoSoft)
BHO: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre1.8.0_45\bin\ssv.dll [2015-06-05] (Oracle Corporation)
BHO: CIESpeechBHO Class -> {8D10F6C4-0E01-4BD4-8601-11AC1FDF8126} -> C:\Program Files (x86)\Bluetooth Suite\IEPlugIn.dll [2013-01-25] (Qualcomm Atheros Commnucations)
BHO: Microsoft SkyDrive Pro Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX64\Microsoft Office\Office15\GROOVEEX.DLL [2015-07-14] (Microsoft Corporation)
BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre1.8.0_45\bin\jp2ssv.dll [2015-06-05] (Oracle Corporation)
BHO: ClassicIEBHO Class -> {EA801577-E6AD-4BD5-8F71-4BE0154331A4} -> C:\Program Files\Classic Shell\ClassicIEDLL_64.dll [2015-05-16] (IvoSoft)
BHO-x32: ExplorerBHO Class -> {449D0D6E-2412-4E61-B68F-1CB625CD9E52} -> C:\Program Files\Classic Shell\ClassicExplorer32.dll [2015-05-16] (IvoSoft)
BHO-x32: ClassicIEBHO Class -> {EA801577-E6AD-4BD5-8F71-4BE0154331A4} -> C:\Program Files\Classic Shell\ClassicIEDLL_32.dll [2015-05-16] (IvoSoft)
Toolbar: HKLM - Classic Explorer Bar - {553891B7-A0D5-4526-BE18-D3CE461D6310} - C:\Program Files\Classic Shell\ClassicExplorer64.dll [2015-05-16] (IvoSoft)
Toolbar: HKLM-x32 - Classic Explorer Bar - {553891B7-A0D5-4526-BE18-D3CE461D6310} - C:\Program Files\Classic Shell\ClassicExplorer32.dll [2015-05-16] (IvoSoft)
Handler-x32: osf - {D924BDC6-C83A-4BD5-90D0-095128A113D1} - C:\Program Files\Microsoft Office 15\root\Office15\MSOSB.DLL [2015-06-09] (Microsoft Corporation)
Hosts: There are more than one entry in Hosts. See Hosts section of Addition.txt
Tcpip\Parameters: [DhcpNameServer] 10.0.0.138
Tcpip\..\Interfaces\{0B26C385-7A9D-49A9-BFFC-57EDC999C3CF}: [DhcpNameServer] 10.0.0.138
Tcpip\..\Interfaces\{9E42551A-0C90-4C5F-AFBB-CE61E90B5B33}: [DhcpNameServer] 10.0.0.138
FireFox:
========
FF ProfilePath: C:\Users\skotn_000\AppData\Roaming\Mozilla\Firefox\Profiles\puozbh2t.default
FF Plugin: @adobe.com/FlashPlayer -> C:\WINDOWS\system32\Macromed\Flash\NPSWF64_18_0_0_209.dll [2015-07-15] ()
FF Plugin: @java.com/DTPlugin,version=11.45.2 -> C:\Program Files\Java\jre1.8.0_45\bin\dtplugin\npDeployJava1.dll [2015-06-05] (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=11.45.2 -> C:\Program Files\Java\jre1.8.0_45\bin\plugin2\npjp2.dll [2015-06-05] (Oracle Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\WINDOWS\SysWOW64\Macromed\Flash\NPSWF32_18_0_0_209.dll [2015-07-15] ()
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=2.1.42 -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll [2012-06-07] (Intel Corporation)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll [2012-06-07] (Intel Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files\Microsoft Office 15\root\Office15\NPSPWRAP.DLL [2015-06-09] (Microsoft Corporation)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll [2015-07-03] (Adobe Systems Inc.)
FF Plugin HKU\S-1-5-21-3338900602-571765566-1102821152-1002: @tools.google.com/Google Update;version=3 -> C:\Users\skotn_000\AppData\Local\Google\Update\1.3.28.13\npGoogleUpdate3.dll [2015-08-29] (Google Inc.)
FF Plugin HKU\S-1-5-21-3338900602-571765566-1102821152-1002: @tools.google.com/Google Update;version=9 -> C:\Users\skotn_000\AppData\Local\Google\Update\1.3.28.13\npGoogleUpdate3.dll [2015-08-29] (Google Inc.)
FF HKLM\...\Firefox\Extensions: [{4ED1F68A-5463-4931-9384-8FFF5ED91D92}] - C:\Program Files (x86)\McAfee\SiteAdvisor
FF HKLM-x32\...\Thunderbird\Extensions: [
msktbird@mcafee.com] - C:\Program Files\McAfee\MSK
Chrome:
=======
CHR Profile: C:\Users\skotn_000\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (Google Slides) - C:\Users\skotn_000\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2015-05-24]
CHR Extension: (Google Docs) - C:\Users\skotn_000\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2015-05-24]
CHR Extension: (Google Drive) - C:\Users\skotn_000\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2015-05-24]
CHR Extension: (YouTube) - C:\Users\skotn_000\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2015-05-24]
CHR Extension: (OneTab) - C:\Users\skotn_000\AppData\Local\Google\Chrome\User Data\Default\Extensions\chphlpgkkbolifaimnlloiipkdnihall [2015-07-17]
CHR Extension: (Google Search) - C:\Users\skotn_000\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2015-05-24]
CHR Extension: (Google Sheets) - C:\Users\skotn_000\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2015-05-24]
CHR Extension: (AdBlock) - C:\Users\skotn_000\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom [2015-08-04]
CHR Extension: (LoudTronix Helper) - C:\Users\skotn_000\AppData\Local\Google\Chrome\User Data\Default\Extensions\hdfpmjnfglpmofblacoponodofkdongp [2015-05-24]
CHR Extension: (Looper for YouTube) - C:\Users\skotn_000\AppData\Local\Google\Chrome\User Data\Default\Extensions\iggpfpnahkgpnindfkdncknoldgnccdg [2015-08-04]
CHR Extension: (The Great Suspender) - C:\Users\skotn_000\AppData\Local\Google\Chrome\User Data\Default\Extensions\klbibkeccnjlkjkiokjodocebajanakg [2015-07-17]
CHR Extension: (Lyrics Here by Rob W) - C:\Users\skotn_000\AppData\Local\Google\Chrome\User Data\Default\Extensions\lifkpflabnobkgbjpcmocmgcajlecbcp [2015-08-04]
CHR Extension: (Google Mail Checker) - C:\Users\skotn_000\AppData\Local\Google\Chrome\User Data\Default\Extensions\mihcahmgecmbnbcchbopgniflfhgnkff [2015-05-24]
CHR Extension: (Chrome Web Store Payments) - C:\Users\skotn_000\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2015-05-24]
CHR Extension: (Gmail) - C:\Users\skotn_000\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2015-05-24]
CHR HKLM\...\Chrome\Extension: [fheoggkfdfchfphceeifdbepaooicaho] - C:\Program Files (x86)\McAfee\SiteAdvisor\McChPlg.crx <not found>
==================== Services (Whitelisted) ========================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
S3 ALG; C:\Windows\System32\alg.exe [94208 2012-07-26] (Microsoft Corporation) [File not signed]
S3 AllUserInstallAgent; C:\Windows\system32\AUInstallAgent.dll [122368 2012-07-26] (Microsoft Corporation) [File not signed]
S3 AppIDSvc; C:\Windows\System32\appidsvc.dll [37888 2012-07-26] (Microsoft Corporation) [File not signed]
R2 AtherosSvc; C:\Program Files (x86)\Bluetooth Suite\adminservice.exe [227456 2013-01-25] (Qualcomm Atheros Commnucations) [File not signed]
S2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [146600 2015-08-29] (AVAST Software)
R3 AvastVBoxSvc; C:\Program Files\AVAST Software\Avast\ng\vbox\AvastVBoxSVC.exe [4047768 2015-08-29] (Avast Software)
S3 AxInstSV; C:\Windows\System32\AxInstSV.dll [112128 2012-07-26] (Microsoft Corporation) [File not signed]
R2 BITS; C:\Windows\System32\qmgr.dll [826368 2012-07-26] (Microsoft Corporation) [File not signed]
R2 BrcmCardReader; C:\Program Files\Broadcom\MemoryCard\BrcmCardReader.exe [176640 2012-08-21] (Broadcom Corp.) [File not signed]
R3 Browser; C:\Windows\System32\browser.dll [134144 2012-07-26] (Microsoft Corporation) [File not signed]
S3 bthserv; C:\Windows\system32\bthserv.dll [89088 2012-07-26] (Microsoft Corporation) [File not signed]
R2 CCDMonitorService; C:\Program Files (x86)\Acer\Acer Cloud\CCDMonitorService.exe [2615368 2013-02-20] (Acer Incorporated)
S3 CertPropSvc; C:\Windows\System32\certprop.dll [149504 2012-07-26] (Microsoft Corporation) [File not signed]
R2 ClickToRunSvc; C:\Program Files\Microsoft Office 15\ClientX64\OfficeClickToRun.exe [2765496 2015-07-14] (Microsoft Corporation)
R2 DcomLaunch; C:\Windows\system32\rpcss.dll [817152 2012-07-26] (Microsoft Corporation) [File not signed]
R2 DeviceAssociationService; C:\Windows\system32\das.dll [342016 2012-07-26] (Microsoft Corporation) [File not signed]
S3 Disc Soft Lite Bus Service; C:\Program Files\DAEMON Tools Lite\DiscSoftBusService.exe [1272560 2015-05-21] (Disc Soft Ltd)
S3 dot3svc; C:\Windows\System32\dot3svc.dll [252928 2012-07-26] (Microsoft Corporation) [File not signed]
R2 DPS; C:\Windows\system32\dps.dll [197120 2012-07-26] (Microsoft Corporation) [File not signed]
S3 Eaphost; C:\Windows\System32\eapsvc.dll [105472 2012-07-26] (Microsoft Corporation) [File not signed]
S3 EFS; C:\Windows\system32\efssvc.dll [37376 2012-07-26] (Microsoft Corporation) [File not signed]
R3 ePowerSvc; C:\Program Files\Acer\Acer Power Management\ePowerSvc.exe [662088 2013-03-16] (Acer Incorporated)
R2 ETDService; C:\Program Files\Elantech\ETDService.exe [100752 2012-11-20] (ELAN Microelectronics Corp.)
R2 EventSystem; C:\Windows\system32\es.dll [507904 2012-07-26] (Microsoft Corporation) [File not signed]
R2 EventSystem; C:\Windows\SysWOW64\es.dll [394240 2012-07-26] (Microsoft Corporation) [File not signed]
S3 Fax; C:\Windows\system32\fxssvc.exe [669696 2012-07-26] (Microsoft Corporation) [File not signed]
R3 fdPHost; C:\Windows\system32\fdPHost.dll [21504 2012-07-26] (Microsoft Corporation) [File not signed]
R3 FDResPub; C:\Windows\system32\fdrespub.dll [33280 2012-07-26] (Microsoft Corporation) [File not signed]
R2 GfExperienceService; C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe [1155192 2015-08-18] (NVIDIA Corporation)
R2 gpsvc; C:\Windows\System32\gpsvc.dll [1366016 2012-07-26] (Microsoft Corporation) [File not signed]
R3 hidserv; C:\Windows\system32\hidserv.dll [36352 2012-07-26] (Microsoft Corporation) [File not signed]
R3 hidserv; C:\Windows\SysWOW64\hidserv.dll [49152 2012-07-26] (Microsoft Corporation) [File not signed]
S3 hkmsvc; C:\Windows\system32\kmsvc.dll [97792 2012-07-26] (Microsoft Corporation) [File not signed]
R3 HomeGroupProvider; C:\Windows\system32\provsvc.dll [394752 2012-07-26] (Microsoft Corporation) [File not signed]
R3 HomeGroupProvider; C:\Windows\SysWOW64\provsvc.dll [304128 2012-07-26] (Microsoft Corporation) [File not signed]
R2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [165760 2012-07-18] (Intel Corporation)
R3 KeyIso; C:\Windows\system32\keyiso.dll [59904 2012-07-26] (Microsoft Corporation) [File not signed]
R3 KeyIso; C:\Windows\SysWOW64\keyiso.dll [43520 2012-07-26] (Microsoft Corporation) [File not signed]
S3 KtmRm; C:\Windows\system32\msdtckrm.dll [358912 2012-07-26] (Microsoft Corporation) [File not signed]
R2 LanmanWorkstation; C:\Windows\System32\wkssvc.dll [191488 2012-07-26] (Microsoft Corporation) [File not signed]
S3 lltdsvc; C:\Windows\System32\lltdsvc.dll [274944 2012-07-26] (Microsoft Corporation) [File not signed]
R2 lmhosts; C:\Windows\System32\lmhsvc.dll [23040 2012-07-26] (Microsoft Corporation) [File not signed]
S3 MSDTC; C:\Windows\System32\msdtc.exe [144384 2012-07-26] (Microsoft Corporation) [File not signed]
S3 MSiSCSI; C:\Windows\system32\iscsiexe.dll [151552 2012-07-26] (Microsoft Corporation) [File not signed]
S3 msiserver; C:\Windows\System32\msiexec.exe [124416 2012-07-26] (Microsoft Corporation) [File not signed]
S3 msiserver; C:\Windows\SysWOW64\msiexec.exe [62976 2012-07-26] (Microsoft Corporation) [File not signed]
S3 napagent; C:\Windows\system32\qagentRT.dll [428544 2012-07-26] (Microsoft Corporation) [File not signed]
S3 NcaSvc; C:\Windows\System32\ncasvc.dll [161792 2012-07-26] (Microsoft Corporation) [File not signed]
R3 NcdAutoSetup; C:\Windows\System32\NcdAutoSetup.dll [73728 2012-07-26] (Microsoft Corporation) [File not signed]
S3 Netlogon; C:\Windows\system32\netlogon.dll [743936 2012-07-26] (Microsoft Corporation) [File not signed]
S3 Netlogon; C:\Windows\SysWOW64\netlogon.dll [634368 2012-07-26] (Microsoft Corporation) [File not signed]
R3 Netman; C:\Windows\System32\netman.dll [255488 2012-07-26] (Microsoft Corporation) [File not signed]
R2 NOBU; C:\Program Files (x86)\Symantec\Norton Online Backup\NOBuAgent.exe [3943104 2012-08-15] (Symantec Corporation)
R2 nsi; C:\Windows\system32\nsisvc.dll [25600 2012-07-26] (Microsoft Corporation) [File not signed]
R2 NvNetworkService; C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe [1872504 2015-08-18] (NVIDIA Corporation)
R2 NvStreamSvc; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamService.exe [5544568 2015-08-18] (NVIDIA Corporation)
S3 OverwolfUpdater; C:\Program Files (x86)\Overwolf\OverwolfUpdater.exe [1001200 2015-07-19] (Overwolf LTD)
R3 p2pimsvc; C:\Windows\system32\pnrpsvc.dll [329728 2012-07-26] (Microsoft Corporation) [File not signed]
R3 p2psvc; C:\Windows\system32\p2psvc.dll [435712 2012-07-26] (Microsoft Corporation) [File not signed]
S3 PerfHost; C:\Windows\SysWow64\perfhost.exe [20992 2012-07-26] (Microsoft Corporation) [File not signed]
S3 pla; C:\Windows\system32\pla.dll [1379840 2012-07-26] (Microsoft Corporation) [File not signed]
S3 pla; C:\Windows\SysWOW64\pla.dll [1421824 2012-07-26] (Microsoft Corporation) [File not signed]
R2 PnkBstrA; C:\WINDOWS\SysWOW64\PnkBstrA.exe [76152 2015-06-07] ()
S3 PNRPAutoReg; C:\Windows\system32\pnrpauto.dll [26624 2012-07-26] (Microsoft Corporation) [File not signed]
R3 PNRPsvc; C:\Windows\system32\pnrpsvc.dll [329728 2012-07-26] (Microsoft Corporation) [File not signed]
S3 PolicyAgent; C:\Windows\System32\ipsecsvc.dll [474624 2012-07-26] (Microsoft Corporation) [File not signed]
S3 PrintNotify; C:\Windows\system32\spool\DRIVERS\x64\3\PrintConfig.dll [2675200 2012-07-26] (Microsoft Corporation) [File not signed]
S3 QWAVE; C:\Windows\system32\qwave.dll [268800 2012-07-26] (Microsoft Corporation) [File not signed]
S3 RasAuto; C:\Windows\System32\rasauto.dll [99840 2012-07-26] (Microsoft Corporation) [File not signed]
S3 RasMan; C:\Windows\System32\rasmans.dll [358400 2012-07-26] (Microsoft Corporation) [File not signed]
S4 RemoteAccess; C:\Windows\System32\mprdim.dll [107520 2012-07-26] (Microsoft Corporation) [File not signed]
S4 RemoteAccess; C:\Windows\SysWOW64\mprdim.dll [81920 2012-07-26] (Microsoft Corporation) [File not signed]
S4 RemoteRegistry; C:\Windows\system32\regsvc.dll [159744 2012-07-26] (Microsoft Corporation) [File not signed]
R2 RfButtonDriverService; C:\Windows\RfBtnSvc64.exe [96880 2013-07-15] (Dritek System INC.)
S3 RpcLocator; C:\Windows\system32\locator.exe [9728 2012-07-26] (Microsoft Corporation) [File not signed]
R2 RpcSs; C:\Windows\system32\rpcss.dll [817152 2012-07-26] (Microsoft Corporation) [File not signed]
S4 SCardSvr; C:\Windows\System32\SCardSvr.dll [196608 2012-07-26] (Microsoft Corporation) [File not signed]
S3 SCPolicySvc; C:\Windows\System32\certprop.dll [149504 2012-07-26] (Microsoft Corporation) [File not signed]
S3 SDRSVC; C:\Windows\System32\SDRSVC.dll [148480 2012-07-26] (Microsoft Corporation) [File not signed]
S2 SDScannerService; C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe [1738168 2014-06-24] (Safer-Networking Ltd.)
R2 SDUpdateService; C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe [2088408 2014-06-27] (Safer-Networking Ltd.)
R2 SDWSCService; C:\Program Files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe [171928 2014-04-25] (Safer-Networking Ltd.)
R3 seclogon; C:\Windows\system32\seclogon.dll [30720 2012-07-26] (Microsoft Corporation) [File not signed]
R2 SENS; C:\Windows\System32\sens.dll [62976 2012-07-26] (Microsoft Corporation) [File not signed]
S3 SensrSvc; C:\Windows\system32\sensrsvc.dll [161792 2012-07-26] (Microsoft Corporation) [File not signed]
S3 SessionEnv; C:\Windows\system32\sessenv.dll [291328 2012-07-26] (Microsoft Corporation) [File not signed]
S3 SessionEnv; C:\Windows\SysWOW64\sessenv.dll [249344 2012-07-26] (Microsoft Corporation) [File not signed]
S4 SharedAccess; C:\Windows\System32\ipnathlp.dll [438784 2012-07-26] (Microsoft Corporation) [File not signed]
R2 ShellHWDetection; C:\Windows\System32\shsvcs.dll [565760 2012-07-26] (Microsoft Corporation) [File not signed]
R2 ShellHWDetection; C:\Windows\SysWOW64\shsvcs.dll [506368 2012-07-26] (Microsoft Corporation) [File not signed]
S3 SNMPTRAP; C:\Windows\System32\snmptrap.exe [14848 2012-07-26] (Microsoft Corporation) [File not signed]
R2 Spooler; C:\Windows\System32\spoolsv.exe [769024 2012-07-26] (Microsoft Corporation) [File not signed]
R3 SSDPSRV; C:\Windows\System32\ssdpsrv.dll [266240 2012-07-26] (Microsoft Corporation) [File not signed]
S3 SstpSvc; C:\Windows\system32\sstpsvc.dll [81920 2012-07-26] (Microsoft Corporation) [File not signed]
R2 stisvc; C:\Windows\System32\wiaservc.dll [570880 2012-07-26] (Microsoft Corporation) [File not signed]
S3 StorSvc; C:\Windows\system32\storsvc.dll [20992 2012-07-26] (Microsoft Corporation) [File not signed]
S3 StorSvc; C:\Windows\SysWOW64\storsvc.dll [18432 2012-07-26] (Microsoft Corporation) [File not signed]
S3 svsvc; C:\Windows\system32\svsvc.dll [12800 2012-07-26] (Microsoft Corporation) [File not signed]
S3 swprv; C:\Windows\System32\swprv.dll [502784 2012-07-26] (Microsoft Corporation) [File not signed]
S3 TabletInputService; C:\Windows\System32\TabSvc.dll [84480 2012-07-26] (Microsoft Corporation) [File not signed]
S3 TapiSrv; C:\Windows\System32\tapisrv.dll [305664 2012-07-26] (Microsoft Corporation) [File not signed]
S3 TapiSrv; C:\Windows\SysWOW64\tapisrv.dll [245760 2012-07-26] (Microsoft Corporation) [File not signed]
R2 Themes; C:\Windows\system32\themeservice.dll [47104 2012-07-26] (Microsoft Corporation) [File not signed]
R2 TrkWks; C:\Windows\System32\trkwks.dll [119808 2012-07-26] (Microsoft Corporation) [File not signed]
S3 UI0Detect; C:\Windows\system32\UI0Detect.exe [40960 2012-07-26] (Microsoft Corporation) [File not signed]
S3 UmRdpService; C:\Windows\System32\umrdp.dll [250880 2012-07-26] (Microsoft Corporation) [File not signed]
S3 upnphost; C:\Windows\System32\upnphost.dll [520704 2012-07-26] (Microsoft Corporation) [File not signed]
S3 upnphost; C:\Windows\SysWOW64\upnphost.dll [409600 2012-07-26] (Microsoft Corporation) [File not signed]
R3 VaultSvc; C:\Windows\System32\vaultsvc.dll [283648 2012-07-26] (Microsoft Corporation) [File not signed]
S3 vmicheartbeat; C:\Windows\System32\ICSvc.dll [336384 2012-07-26] (Microsoft Corporation) [File not signed]
S3 vmickvpexchange; C:\Windows\System32\ICSvc.dll [336384 2012-07-26] (Microsoft Corporation) [File not signed]
S3 vmicrdv; C:\Windows\System32\ICSvc.dll [336384 2012-07-26] (Microsoft Corporation) [File not signed]
S3 vmicshutdown; C:\Windows\System32\ICSvc.dll [336384 2012-07-26] (Microsoft Corporation) [File not signed]
S3 vmictimesync; C:\Windows\System32\ICSvc.dll [336384 2012-07-26] (Microsoft Corporation) [File not signed]
S3 vmicvss; C:\Windows\System32\ICSvc.dll [336384 2012-07-26] (Microsoft Corporation) [File not signed]
S3 W32Time; C:\Windows\system32\w32time.dll [358400 2012-07-26] (Microsoft Corporation) [File not signed]
S3 wbengine; C:\Windows\system32\wbengine.exe [1616896 2012-07-26] (Microsoft Corporation) [File not signed]
S3 WbioSrvc; C:\Windows\System32\wbiosrvc.dll [335872 2012-07-26] (Microsoft Corporation) [File not signed]
R3 WdiServiceHost; C:\Windows\system32\wdi.dll [109568 2012-07-26] (Microsoft Corporation) [File not signed]
R3 WdiServiceHost; C:\Windows\SysWOW64\wdi.dll [96768 2012-07-26] (Microsoft Corporation) [File not signed]
R3 WdiSystemHost; C:\Windows\system32\wdi.dll [109568 2012-07-26] (Microsoft Corporation) [File not signed]
R3 WdiSystemHost; C:\Windows\SysWOW64\wdi.dll [96768 2012-07-26] (Microsoft Corporation) [File not signed]
S3 Wecsvc; C:\Windows\system32\wecsvc.dll [218112 2012-07-26] (Microsoft Corporation) [File not signed]
S3 wercplsupport; C:\Windows\System32\wercplsupport.dll [84992 2012-07-26] (Microsoft Corporation) [File not signed]
S3 WiaRpc; C:\Windows\System32\wiarpc.dll [65536 2012-07-26] (Microsoft Corporation) [File not signed]
S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [16024 2015-01-31] (Microsoft Corporation)
R2 Winmgmt; C:\Windows\system32\wbem\WMIsvc.dll [219648 2012-07-26] (Microsoft Corporation) [File not signed]
S3 wmiApSrv; C:\Windows\system32\wbem\WmiApSrv.exe [198144 2012-07-26] (Microsoft Corporation) [File not signed]
S3 WPCSvc; C:\Windows\System32\wpcsvc.dll [11776 2012-07-26] (Microsoft Corporation) [File not signed]
S3 WPCSvc; C:\Windows\SysWOW64\wpcsvc.dll [10240 2012-07-26] (Microsoft Corporation) [File not signed]
R3 wuauserv; C:\Windows\system32\wuaueng.dll [3286016 2014-11-15] (Microsoft Corporation) [File not signed]
S3 wudfsvc; C:\Windows\System32\WUDFSvc.dll [84992 2012-07-26] (Microsoft Corporation) [File not signed]
===================== Drivers (Whitelisted) ==========================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
S3 1394ohci; C:\Windows\System32\drivers\1394ohci.sys [226304 2012-07-26] (Microsoft Corporation) [File not signed]
S3 acpipagr; C:\Windows\System32\drivers\acpipagr.sys [10240 2012-07-26] (Microsoft Corporation) [File not signed]
S3 AcpiPmi; C:\Windows\System32\drivers\acpipmi.sys [12288 2012-07-26] (Microsoft Corporation) [File not signed]
S3 acpitime; C:\Windows\System32\drivers\acpitime.sys [10752 2012-07-26] (Microsoft Corporation) [File not signed]
S3 AppID; C:\Windows\system32\drivers\appid.sys [79360 2012-07-26] (Microsoft Corporation) [File not signed]
R2 aswHwid; C:\Windows\system32\drivers\aswHwid.sys [28656 2015-08-29] (AVAST Software)
R2 aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [90968 2015-08-29] (AVAST Software)
R1 aswRdr; C:\Windows\system32\drivers\aswRdr2.sys [93528 2015-08-29] (AVAST Software)
S0 aswRvrt; C:\Windows\System32\Drivers\aswRvrt.sys [65224 2015-08-29] (AVAST Software)
R1 aswSnx; C:\Windows\system32\drivers\aswSnx.sys [1048344 2015-08-29] (AVAST Software)
R1 aswSP; C:\Windows\system32\drivers\aswSP.sys [447944 2015-08-29] (AVAST Software)
S2 aswStm; C:\Windows\system32\drivers\aswStm.sys [150672 2015-08-29] (AVAST Software)
R0 aswVmm; C:\Windows\System32\Drivers\aswVmm.sys [274808 2015-08-29] (AVAST Software)
S3 AsyncMac; C:\Windows\system32\DRIVERS\asyncmac.sys [26624 2012-07-26] (Microsoft Corporation) [File not signed]
R3 athr; C:\Windows\system32\DRIVERS\athw8x.sys [3747840 2013-01-21] (Qualcomm Atheros Communications, Inc.) [File not signed]
R1 BasicDisplay; C:\Windows\System32\drivers\BasicDisplay.sys [48640 2012-07-26] (Microsoft Corporation) [File not signed]
R1 BasicRender; C:\Windows\System32\drivers\BasicRender.sys [29696 2012-07-26] (Microsoft Corporation) [File not signed]
S3 BCM43XX; C:\Windows\system32\DRIVERS\bcmwl63a.sys [5139968 2012-06-02] (Broadcom Corporation) [File not signed]
R3 bowser; C:\Windows\System32\DRIVERS\bowser.sys [101888 2012-07-26] (Microsoft Corporation) [File not signed]
S3 BTATH_LWFLT; C:\Windows\system32\DRIVERS\btath_lwflt.sys [77464 2013-01-25] (Qualcomm Atheros)
S3 BthHFEnum; C:\Windows\System32\drivers\bthhfenum.sys [51200 2012-07-26] (Microsoft Corporation) [File not signed]
S3 BthLEEnum; C:\Windows\system32\DRIVERS\BthLEEnum.sys [202752 2012-07-26] (Microsoft Corporation) [File not signed]
S3 BTHMODEM; C:\Windows\System32\drivers\bthmodem.sys [65536 2012-07-26] (Microsoft Corporation) [File not signed]
S3 BthPan; C:\Windows\system32\DRIVERS\bthpan.sys [119808 2012-07-26] (Microsoft Corporation) [File not signed]
R1 ccSet_NARA; C:\Windows\system32\drivers\NARAx64\0401000.00E\ccSetx64.sys [168608 2012-05-26] (Symantec Corporation)
S4 cdfs; C:\Windows\System32\DRIVERS\cdfs.sys [108544 2012-07-26] (Microsoft Corporation) [File not signed]
R1 cdrom; C:\Windows\System32\drivers\cdrom.sys [174080 2012-07-26] (Microsoft Corporation) [File not signed]
S3 circlass; C:\Windows\System32\drivers\circlass.sys [45056 2012-07-26] (Microsoft Corporation) [File not signed]
R3 CmBatt; C:\Windows\System32\drivers\CmBatt.sys [25600 2012-07-26] (Microsoft Corporation) [File not signed]
R3 CompositeBus; C:\Windows\System32\drivers\CompositeBus.sys [36352 2012-07-26] (Microsoft Corporation) [File not signed]
R3 condrv; C:\Windows\System32\drivers\condrv.sys [33792 2012-07-26] (Microsoft Corporation) [File not signed]
R1 discache; C:\Windows\System32\drivers\discache.sys [50688 2012-07-26] (Microsoft Corporation) [File not signed]
S3 dmvsc; C:\Windows\System32\drivers\dmvsc.sys [33280 2012-07-26] (Microsoft Corporation) [File not signed]
R3 dtlitescsibus; C:\Windows\System32\drivers\dtlitescsibus.sys [30264 2015-05-25] (Disc Soft Ltd)
S3 ErrDev; C:\Windows\System32\drivers\errdev.sys [10240 2012-07-26] (Microsoft Corporation) [File not signed]
S3 exfat; C:\Windows\System32\Drivers\exfat.sys [194560 2012-07-26] (Microsoft Corporation) [File not signed]
S3 fdc; C:\Windows\System32\drivers\fdc.sys [30720 2012-07-26] (Microsoft Corporation) [File not signed]
S3 Filetrace; C:\Windows\System32\drivers\filetrace.sys [34816 2012-07-26] (Microsoft Corporation) [File not signed]
S3 flpydisk; C:\Windows\System32\drivers\flpydisk.sys [24576 2012-07-26] (Microsoft Corporation) [File not signed]
S3 gencounter; C:\Windows\System32\drivers\vmgencounter.sys [12288 2012-07-26] (Microsoft Corporation) [File not signed]
S3 HidBatt; C:\Windows\System32\drivers\HidBatt.sys [27136 2012-07-26] (Microsoft Corporation) [File not signed]
S3 HidIr; C:\Windows\System32\drivers\hidir.sys [46080 2012-07-26] (Microsoft Corporation) [File not signed]
S3 hyperkbd; C:\Windows\System32\drivers\hyperkbd.sys [11776 2012-07-26] (Microsoft Corporation) [File not signed]
S3 HyperVideo; C:\Windows\system32\DRIVERS\HyperVideo.sys [24576 2012-07-26] (Microsoft Corporation) [File not signed]
R3 igfx; C:\Windows\system32\DRIVERS\igdkmd64.sys [5343584 2012-10-23] (Intel Corporation) [File not signed]
R3 IntcDAud; C:\Windows\system32\DRIVERS\IntcDAud.sys [342528 2012-06-19] (Intel(R) Corporation) [File not signed]
S3 IpFilterDriver; C:\Windows\System32\DRIVERS\ipfltdrv.sys [89088 2012-07-26] (Microsoft Corporation) [File not signed]
S3 IPNAT; C:\Windows\System32\drivers\ipnat.sys [145920 2012-07-26] (Microsoft Corporation) [File not signed]
S3 IRENUM; C:\Windows\System32\drivers\irenum.sys [17920 2012-07-26] (Microsoft Corporation) [File not signed]
R3 k57nd60a; C:\Windows\system32\DRIVERS\k57nd60a.sys [425472 2012-06-02] (Broadcom Corporation) [File not signed]
R3 kdnic; C:\Windows\system32\DRIVERS\kdnic.sys [18432 2012-07-26] (Microsoft Corporation) [File not signed]
R3 ksthunk; C:\Windows\system32\drivers\ksthunk.sys [21376 2012-07-26] (Microsoft Corporation) [File not signed]
R2 lltdio; C:\Windows\system32\DRIVERS\lltdio.sys [60416 2012-07-26] (Microsoft Corporation) [File not signed]
R2 luafv; C:\Windows\system32\drivers\luafv.sys [134144 2012-07-26] (Microsoft Corporation) [File not signed]
S3 Modem; C:\Windows\System32\drivers\modem.sys [40448 2012-07-26] (Microsoft Corporation) [File not signed]
R3 mrxsmb10; C:\Windows\System32\DRIVERS\mrxsmb10.sys [279552 2012-07-26] (Microsoft Corporation) [File not signed]
S3 MsBridge; C:\Windows\system32\DRIVERS\bridge.sys [129536 2012-07-26] (Microsoft Corporation) [File not signed]
S3 mshidkmdf; C:\Windows\System32\drivers\mshidkmdf.sys [8704 2012-07-26] (Microsoft Corporation) [File not signed]
S3 mshidumdf; C:\Windows\System32\drivers\mshidumdf.sys [10752 2012-07-26] (Microsoft Corporation) [File not signed]
S3 MSKSSRV; C:\Windows\system32\drivers\MSKSSRV.sys [11008 2012-07-26] (Microsoft Corporation) [File not signed]
S3 MsLldp; C:\Windows\system32\DRIVERS\mslldp.sys [68608 2012-07-26] (Microsoft Corporation) [File not signed]
S3 MSPCLOCK; C:\Windows\system32\drivers\MSPCLOCK.sys [7168 2012-07-26] (Microsoft Corporation) [File not signed]
S3 MSPQM; C:\Windows\system32\drivers\MSPQM.sys [6912 2012-07-26] (Microsoft Corporation) [File not signed]
S3 MSTEE; C:\Windows\system32\drivers\MSTEE.sys [8192 2012-07-26] (Microsoft Corporation) [File not signed]
S3 MTConfig; C:\Windows\System32\drivers\MTConfig.sys [14848 2012-07-26] (Microsoft Corporation) [File not signed]
R2 NativeWifiP; C:\Windows\system32\DRIVERS\nwifi.sys [427520 2012-07-26] (Microsoft Corporation) [File not signed]
S3 NdisCap; C:\Windows\system32\DRIVERS\ndiscap.sys [46592 2012-07-26] (Microsoft Corporation) [File not signed]
R3 Ndisuio; C:\Windows\system32\DRIVERS\ndisuio.sys [58880 2012-07-26] (Microsoft Corporation) [File not signed]
R3 NdisWan; C:\Windows\system32\DRIVERS\ndiswan.sys [174080 2012-07-26] (Microsoft Corporation) [File not signed]
S3 NDISWANLEGACY; C:\Windows\system32\DRIVERS\ndiswan.sys [174080 2012-07-26] (Microsoft Corporation) [File not signed]
R2 Ndu; C:\Windows\System32\drivers\Ndu.sys [97792 2012-07-26] (Microsoft Corporation) [File not signed]
R1 NetBIOS; C:\Windows\System32\DRIVERS\netbios.sys [46080 2012-07-26] (Microsoft Corporation) [File not signed]
R1 NetBT; C:\Windows\System32\DRIVERS\netbt.sys [331776 2012-07-26] (Microsoft Corporation) [File not signed]
R0 ngvss; C:\Windows\System32\Drivers\ngvss.sys [115152 2015-08-29] (AVAST Software)
R1 Npfs; C:\Windows\System32\Drivers\Npfs.sys [49152 2012-07-26] (Microsoft Corporation) [File not signed]
R1 npsvctrig; C:\Windows\System32\drivers\npsvctrig.sys [23552 2012-07-26] (Microsoft Corporation) [File not signed]
R1 nsiproxy; C:\Windows\System32\drivers\nsiproxy.sys [34304 2012-07-26] (Microsoft Corporation) [File not signed]
R1 Null; C:\Windows\System32\Drivers\Null.sys [5632 2012-07-26] (Microsoft Corporation) [File not signed]
R3 NvStreamKms; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys [19576 2015-08-18] (NVIDIA Corporation)
R3 nvvad_WaveExtensible; C:\Windows\system32\drivers\nvvad64v.sys [50472 2015-08-11] (NVIDIA Corporation)
S3 Parport; C:\Windows\System32\drivers\parport.sys [105984 2012-07-26] (Microsoft Corporation) [File not signed]
R2 PEAUTH; C:\Windows\System32\drivers\peauth.sys [805376 2013-04-09] (Microsoft Corporation) [File not signed]
R3 PptpMiniport; C:\Windows\system32\DRIVERS\raspptp.sys [114176 2012-07-26] (Microsoft Corporation) [File not signed]
R3 Ps2Kb2Hid; C:\Windows\System32\drivers\aPs2Kb2Hid.sys [26736 2013-07-15] (Dritek System Inc.)
R1 Psched; C:\Windows\system32\DRIVERS\pacer.sys [145408 2012-07-26] (Microsoft Corporation) [File not signed]
S3 QWAVEdrv; C:\Windows\system32\drivers\qwavedrv.sys [46592 2012-07-26] (Microsoft Corporation) [File not signed]
S3 RasAcd; C:\Windows\System32\DRIVERS\rasacd.sys [16384 2012-07-26] (Microsoft Corporation) [File not signed]
R3 RasAgileVpn; C:\Windows\system32\DRIVERS\AgileVpn.sys [68608 2012-07-26] (Microsoft Corporation) [File not signed]
R3 Rasl2tp; C:\Windows\system32\DRIVERS\rasl2tp.sys [124928 2012-07-26] (Microsoft Corporation) [File not signed]
R3 RasPppoe; C:\Windows\system32\DRIVERS\raspppoe.sys [81920 2012-07-26] (Microsoft Corporation) [File not signed]
R3 RasSstp; C:\Windows\system32\DRIVERS\rassstp.sys [92672 2012-07-26] (Microsoft Corporation) [File not signed]
R3 rdpbus; C:\Windows\System32\drivers\rdpbus.sys [22528 2012-07-26] (Microsoft Corporation) [File not signed]
S3 RDPDR; C:\Windows\System32\drivers\rdpdr.sys [179712 2012-07-26] (Microsoft Corporation) [File not signed]
R2 rspndr; C:\Windows\system32\DRIVERS\rspndr.sys [78848 2012-07-26] (Microsoft Corporation) [File not signed]
S3 s3cap; C:\Windows\System32\drivers\vms3cap.sys [7168 2012-07-26] (Microsoft Corporation) [File not signed]
S3 scfilter; C:\Windows\System32\DRIVERS\scfilter.sys [36864 2012-07-26] (Microsoft Corporation) [File not signed]
R2 secdrv; C:\Windows\System32\Drivers\secdrv.sys [23040 2012-07-26] (Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.) [File not signed]
S3 SerCx; C:\Windows\System32\drivers\SerCx.sys [62976 2012-07-26] (Microsoft Corporation) [File not signed]
S3 Serenum; C:\Windows\System32\drivers\serenum.sys [23040 2012-07-26] (Microsoft Corporation) [File not signed]
S3 Serial; C:\Windows\System32\drivers\serial.sys [76800 2012-07-26] (Microsoft Corporation) [File not signed]
S3 sfloppy; C:\Windows\System32\drivers\sfloppy.sys [16896 2012-07-26] (Microsoft Corporation) [File not signed]
S3 SpbCx; C:\Windows\System32\drivers\SpbCx.sys [59392 2012-07-26] (Microsoft Corporation) [File not signed]
R3 srv; C:\Windows\System32\DRIVERS\srv.sys [416768 2012-07-26] (Microsoft Corporation) [File not signed]
S3 ssudobex; C:\Windows\system32\DRIVERS\ssudobex.sys [206080 2014-01-22] (DEVGURU Co., LTD.(
www.devguru.co.kr))
R2 tcpipreg; C:\Windows\System32\drivers\tcpipreg.sys [45056 2012-07-26] (Microsoft Corporation) [File not signed]
R1 tdx; C:\Windows\system32\DRIVERS\tdx.sys [117248 2012-07-26] (Microsoft Corporation) [File not signed]
S3 TsUsbFlt; C:\Windows\System32\drivers\tsusbflt.sys [57344 2012-07-26] (Microsoft Corporation) [File not signed]
S3 TsUsbGD; C:\Windows\System32\drivers\TsUsbGD.sys [30208 2012-07-26] (Microsoft Corporation) [File not signed]
R3 tunnel; C:\Windows\system32\DRIVERS\tunnel.sys [149504 2012-07-26] (Microsoft Corporation) [File not signed]
R3 umbus; C:\Windows\System32\drivers\umbus.sys [48128 2012-07-26] (Microsoft Corporation) [File not signed]
S3 UmPass; C:\Windows\System32\drivers\umpass.sys [11776 2012-07-26] (Microsoft Corporation) [File not signed]
R2 VBoxAswDrv; C:\Program Files\AVAST Software\Avast\ng\vbox\VBoxAswDrv.sys [273824 2015-08-29] (Avast Software)
S3 VMBusHID; C:\Windows\System32\drivers\VMBusHID.sys [22144 2012-07-26] (Microsoft Corporation) [File not signed]
R3 vwifibus; C:\Windows\System32\drivers\vwifibus.sys [24064 2012-07-26] (Microsoft Corporation) [File not signed]
R1 vwififlt; C:\Windows\system32\DRIVERS\vwififlt.sys [64000 2012-07-26] (Microsoft Corporation) [File not signed]
R3 vwifimp; C:\Windows\system32\DRIVERS\vwifimp.sys [17920 2012-07-26] (Microsoft Corporation) [File not signed]
S3 WacomPen; C:\Windows\System32\drivers\wacompen.sys [27008 2012-07-26] (Microsoft Corporation) [File not signed]
S3 WinUSB; C:\Windows\system32\DRIVERS\WinUSB.sys [57344 2012-07-26] (Microsoft Corporation) [File not signed]
R3 WmiAcpi; C:\Windows\System32\drivers\wmiacpi.sys [17408 2012-07-26] (Microsoft Corporation) [File not signed]
S3 wpcfltr; C:\Windows\System32\DRIVERS\wpcfltr.sys [45056 2012-07-26] (Microsoft Corporation) [File not signed]
S3 WpdUpFltr; C:\Windows\System32\drivers\WpdUpFltr.sys [19968 2012-07-26] (Microsoft Corporation) [File not signed]
S3 WudfPf; C:\Windows\System32\drivers\WudfPf.sys [87040 2012-07-26] (Microsoft Corporation) [File not signed]
S3 WUDFRd; C:\Windows\System32\drivers\WUDFRd.sys [198656 2012-07-26] (Microsoft Corporation) [File not signed]
S3 WUDFWpdFs; C:\Windows\system32\DRIVERS\WUDFRd.sys [198656 2012-07-26] (Microsoft Corporation) [File not signed]
R4 AVGIDSHA; system32\DRIVERS\avgidsha.sys [X]
R4 Avgrkx64; system32\DRIVERS\avgrkx64.sys [X]
S3 EagleX64; \??\C:\WINDOWS\system32\drivers\EagleX64.sys [X]
==================== NetSvcs (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
==================== One Month Created files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2015-08-30 16:05 - 2015-08-30 16:06 - 00047775 _____ C:\Users\skotn_000\Desktop\FRST.txt
2015-08-30 16:05 - 2015-08-30 16:06 - 00000000 ____D C:\FRST
2015-08-30 16:02 - 2015-08-30 16:03 - 00112640 _____ (forum.viry.cz) C:\Users\skotn_000\Desktop\FRSTLauncher.exe
2015-08-30 16:02 - 2015-08-30 16:02 - 00112640 _____ (forum.viry.cz) C:\Users\skotn_000\Downloads\Nepotvrzeno 331359.crdownload
2015-08-30 16:01 - 2015-08-30 16:01 - 00112640 _____ (forum.viry.cz) C:\Users\skotn_000\Downloads\Nepotvrzeno 559114.crdownload
2015-08-30 15:52 - 2015-08-30 15:52 - 02186752 _____ (Farbar) C:\Users\skotn_000\Desktop\FRST64.exe
2015-08-29 21:39 - 2015-08-29 21:39 - 00001926 _____ C:\Users\Public\Desktop\Avast Free Antivirus.lnk
2015-08-29 21:39 - 2015-08-29 21:39 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AVAST Software
2015-08-29 21:38 - 2015-08-29 21:38 - 01048856 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswsnx.sys.1440877136656
2015-08-29 21:38 - 2015-08-29 21:38 - 01048344 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswsnx.sys
2015-08-29 21:38 - 2015-08-29 21:38 - 00447944 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswSP.sys
2015-08-29 21:38 - 2015-08-29 21:38 - 00378880 _____ (AVAST Software) C:\WINDOWS\system32\aswBoot.exe
2015-08-29 21:38 - 2015-08-29 21:38 - 00274808 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswVmm.sys
2015-08-29 21:38 - 2015-08-29 21:38 - 00150672 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswStm.sys
2015-08-29 21:38 - 2015-08-29 21:38 - 00115152 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\ngvss.sys
2015-08-29 21:38 - 2015-08-29 21:38 - 00093528 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswRdr2.sys
2015-08-29 21:38 - 2015-08-29 21:38 - 00090968 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswMonFlt.sys
2015-08-29 21:38 - 2015-08-29 21:38 - 00065224 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswRvrt.sys
2015-08-29 21:38 - 2015-08-29 21:38 - 00043112 _____ (AVAST Software) C:\WINDOWS\avastSS.scr
2015-08-29 21:38 - 2015-08-29 21:38 - 00028656 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswHwid.sys
2015-08-29 21:38 - 2015-08-29 21:38 - 00003924 _____ C:\WINDOWS\System32\Tasks\avast! Emergency Update
2015-08-29 21:36 - 2015-08-29 21:36 - 00000000 ____D C:\Program Files\AVAST Software
2015-08-29 18:45 - 2015-07-05 12:08 - 00300704 ____N (Microsoft Corporation) C:\WINDOWS\system32\MpSigStub.exe
2015-08-29 18:14 - 2015-08-29 18:14 - 00502092 _____ C:\WINDOWS\PFRO.log
2015-08-29 18:11 - 2015-08-29 18:12 - 115845912 _____ (AVG Technologies) C:\Users\skotn_000\Downloads\avg_tuh_stf_all_2015_638_24c43.exe
2015-08-29 17:53 - 2015-08-29 17:53 - 00000000 ____D C:\Users\skotn_000\AppData\Roaming\AVG2015
2015-08-29 17:52 - 2015-08-29 21:01 - 00000000 ___HD C:\$AVG
2015-08-29 17:52 - 2015-08-29 21:01 - 00000000 ____D C:\ProgramData\AVG2015
2015-08-29 17:52 - 2015-08-29 17:52 - 00000000 ____D C:\Users\skotn_000\AppData\Roaming\TuneUp Software
2015-08-29 17:51 - 2015-08-29 17:51 - 00000000 ____D C:\Program Files (x86)\AVG
2015-08-29 17:48 - 2015-08-29 21:34 - 00000000 ____D C:\Users\skotn_000\AppData\Local\Avg2015
2015-08-29 17:48 - 2015-08-29 21:34 - 00000000 ____D C:\ProgramData\MFAData
2015-08-29 17:48 - 2015-08-29 17:48 - 00000000 ____D C:\Users\skotn_000\AppData\Local\MFAData
2015-08-29 17:47 - 2015-08-29 21:34 - 00000000 ____D C:\Program Files\Common Files\AV
2015-08-29 17:47 - 2015-08-29 17:47 - 00000034 _____ C:\WINDOWS\AvastEmUpdate.ini
2015-08-29 17:47 - 2015-08-29 17:47 - 00000000 ____D C:\WINDOWS\System32\Tasks\AVAST Software
2015-08-29 17:41 - 2015-08-29 17:41 - 05053040 _____ (AVG Technologies) C:\Users\skotn_000\Downloads\avg_free_stb_all_2015_ltst_612.exe
2015-08-29 17:23 - 2015-08-29 17:23 - 00000000 ____D C:\Users\skotn_000\AppData\Roaming\AVAST Software
2015-08-29 17:21 - 2015-08-29 17:26 - 00000000 ____D C:\WINDOWS\SysWOW64\vbox
2015-08-29 17:21 - 2015-08-29 17:26 - 00000000 ____D C:\WINDOWS\system32\vbox
2015-08-29 17:15 - 2015-08-29 17:15 - 05500000 _____ (Avast Software s.r.o.) C:\Users\skotn_000\Downloads\avast_free_antivirus_setup_online.exe
2015-08-27 17:05 - 2015-08-27 17:27 - 00000000 ____D C:\Users\skotn_000\Downloads\Fable III (CZ) (2011) - t2k9
2015-08-27 17:01 - 2015-08-27 17:03 - 00000000 ____D C:\Users\skotn_000\Downloads\STAR_WARS_KOTOR_1+2_SCORE
2015-08-27 16:40 - 2015-08-27 16:40 - 00000000 ____D C:\Users\skotn_000\Documents\Larian Studios
2015-08-27 16:38 - 2015-08-27 16:38 - 00001368 _____ C:\Users\Public\Desktop\Divinity - Original Sin.lnk
2015-08-27 16:38 - 2015-08-27 16:38 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Larian Studios
2015-08-27 16:11 - 2015-08-27 16:11 - 00000000 ____D C:\Program Files (x86)\Larian Studios
2015-08-27 15:13 - 2015-08-27 15:03 - 08901682 _____ C:\Users\skotn_000\Desktop\Data.zip
2015-08-27 14:12 - 2015-08-27 14:21 - 961977188 _____ C:\Users\skotn_000\Downloads\Full_0.3.rar
2015-08-26 22:51 - 2015-08-26 22:51 - 00000000 _____ C:\WINDOWS\setuperr.log
2015-08-26 22:50 - 2015-08-11 06:52 - 00069416 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvaudcap32v.dll
2015-08-26 22:50 - 2015-08-11 06:52 - 00050472 _____ (NVIDIA Corporation) C:\WINDOWS\system32\Drivers\nvvad64v.sys
2015-08-25 11:13 - 2015-08-25 11:13 - 01605632 _____ C:\Users\skotn_000\Desktop\adwcleaner_5.003.exe
2015-08-24 23:03 - 2015-08-24 23:03 - 02104188 _____ C:\Users\skotn_000\Desktop\minecraft_Skyblock2.1.zip
2015-08-24 19:40 - 2015-08-24 19:41 - 00098504 _____ C:\Users\skotn_000\Desktop\LoL Summoner Information (v4.9.1) Setup.exe
2015-08-21 21:30 - 2015-08-21 21:30 - 00000000 ____D C:\Users\skotn_000\AppData\Roaming\0ad
2015-08-21 21:30 - 2015-08-21 21:30 - 00000000 ____D C:\Users\skotn_000\AppData\Local\0ad
2015-08-21 19:52 - 2015-08-21 19:52 - 00001228 _____ C:\Users\skotn_000\Desktop\Revo Uninstaller.lnk
2015-08-21 19:52 - 2015-08-21 19:52 - 00000000 ____D C:\Program Files (x86)\VS Revo Group
2015-08-21 19:41 - 2015-08-21 19:41 - 00000000 ____D C:\Users\skotn_000\AppData\Local\jwProgramy
2015-08-21 19:38 - 2015-08-21 19:38 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\jwDuplFiles
2015-08-21 19:38 - 2015-08-21 19:38 - 00000000 ____D C:\Program Files (x86)\jwDuplFiles
2015-08-21 18:00 - 2015-08-21 18:00 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Whigs and Tories Beta
2015-08-19 23:11 - 2015-08-19 23:14 - 00000000 ____D C:\Users\skotn_000\AppData\Local\NVIDIA Corporation
2015-08-19 23:11 - 2015-08-19 23:12 - 00000000 ____D C:\Users\skotn_000\AppData\Local\NVIDIA
2015-08-19 23:11 - 2015-08-19 23:11 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\NVIDIA Corporation
2015-08-19 23:11 - 2015-08-18 01:30 - 01423120 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvspcap.dll
2015-08-19 23:11 - 2015-08-18 01:30 - 01316184 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvspbridge.dll
2015-08-19 23:11 - 2015-08-18 01:29 - 01756608 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvspbridge64.dll
2015-08-19 23:11 - 2015-08-18 01:29 - 01710568 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvspcap64.dll
2015-08-19 23:08 - 2015-08-19 23:08 - 00000000 ____D C:\WINDOWS\SysWOW64\NV
2015-08-19 23:08 - 2015-08-19 23:08 - 00000000 ____D C:\WINDOWS\system32\NV
2015-08-19 23:07 - 2015-08-07 06:34 - 06883448 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvcpl.dll
2015-08-19 23:07 - 2015-08-07 06:34 - 03492144 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvsvc64.dll
2015-08-19 23:07 - 2015-08-07 06:34 - 02558768 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvsvcr.dll
2015-08-19 23:07 - 2015-08-07 06:34 - 01061168 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nv3dappshext.dll
2015-08-19 23:07 - 2015-08-07 06:34 - 00937592 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvvsvc.exe
2015-08-19 23:07 - 2015-08-07 06:34 - 00385328 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvmctray.dll
2015-08-19 23:07 - 2015-08-07 06:34 - 00074872 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nv3dappshextr.dll
2015-08-19 23:07 - 2015-08-07 06:34 - 00062768 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvshext.dll
2015-08-19 23:07 - 2015-08-03 12:12 - 05133709 _____ C:\WINDOWS\system32\nvcoproc.bin
2015-08-19 22:52 - 2015-08-11 06:52 - 00072504 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvaudcap64v.dll
2015-08-19 22:52 - 2015-08-07 13:06 - 22520624 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvoglv64.dll
2015-08-19 22:52 - 2015-08-07 13:06 - 18540336 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvoglv32.dll
2015-08-19 22:52 - 2015-08-07 13:06 - 17124832 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvwgf2umx.dll
2015-08-19 22:52 - 2015-08-07 13:06 - 16630096 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvopencl.dll
2015-08-19 22:52 - 2015-08-07 13:06 - 15510112 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvd3dumx.dll
2015-08-19 22:52 - 2015-08-07 13:06 - 14928048 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvcuda.dll
2015-08-19 22:52 - 2015-08-07 13:06 - 14673920 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvwgf2um.dll
2015-08-19 22:52 - 2015-08-07 13:06 - 13656016 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvopencl.dll
2015-08-19 22:52 - 2015-08-07 13:06 - 12513288 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvd3dum.dll
2015-08-19 22:52 - 2015-08-07 13:06 - 12179496 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvcuda.dll
2015-08-19 22:52 - 2015-08-07 13:06 - 11076216 _____ (NVIDIA Corporation) C:\WINDOWS\system32\Drivers\nvlddmkm.sys
2015-08-19 22:52 - 2015-08-07 13:06 - 02937648 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvcuvid.dll
2015-08-19 22:52 - 2015-08-07 13:06 - 02624816 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvcuvid.dll
2015-08-19 22:52 - 2015-08-07 13:06 - 01898104 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvdispco6435560.dll
2015-08-19 22:52 - 2015-08-07 13:06 - 01558832 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvdispgenco6435560.dll
2015-08-19 22:52 - 2015-08-07 13:06 - 01104440 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvumdshimx.dll
2015-08-19 22:52 - 2015-08-07 13:06 - 01063216 _____ (NVIDIA Corporation) C:\WINDOWS\system32\NvIFR64.dll
2015-08-19 22:52 - 2015-08-07 13:06 - 01059960 _____ (NVIDIA Corporation) C:\WINDOWS\system32\NvFBC64.dll
2015-08-19 22:52 - 2015-08-07 13:06 - 00985208 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\NvIFR.dll
2015-08-19 22:52 - 2015-08-07 13:06 - 00942688 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvumdshim.dll
2015-08-19 22:52 - 2015-08-07 13:06 - 00931448 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\NvFBC.dll
2015-08-19 22:52 - 2015-08-07 13:06 - 00177088 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvinitx.dll
2015-08-19 22:52 - 2015-08-07 13:06 - 00155792 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvinit.dll
2015-08-19 22:52 - 2015-08-07 13:06 - 00150648 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvoglshim64.dll
2015-08-19 22:52 - 2015-08-07 13:06 - 00128512 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvoglshim32.dll
2015-08-19 22:52 - 2015-08-07 13:06 - 00033050 _____ C:\WINDOWS\system32\nvinfo.pb
2015-08-19 22:52 - 2015-08-07 13:06 - 00031352 _____ (NVIDIA Corporation) C:\WINDOWS\system32\Drivers\nvpciflt.sys
2015-08-19 22:51 - 2015-08-07 13:06 - 42840184 _____ C:\WINDOWS\system32\nvcompiler.dll
2015-08-19 22:51 - 2015-08-07 13:06 - 37819000 _____ C:\WINDOWS\SysWOW64\nvcompiler.dll
2015-08-19 22:51 - 2015-08-07 13:06 - 03518248 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvapi64.dll
2015-08-19 22:51 - 2015-08-07 13:06 - 03106384 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvapi.dll
2015-08-13 20:21 - 2015-08-13 20:21 - 00000954 _____ C:\Users\skotn_000\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\osu!.lnk
2015-08-13 20:21 - 2015-08-13 20:21 - 00000946 _____ C:\Users\skotn_000\Desktop\osu!.lnk
2015-08-13 20:20 - 2015-08-24 19:26 - 00000000 ____D C:\Users\skotn_000\AppData\Local\osu!
2015-08-13 20:15 - 2015-08-13 20:15 - 00000516 _____ C:\Users\skotn_000\Desktop\Play cRPG.lnk
2015-08-13 20:01 - 2015-08-13 20:01 - 00041984 _____ C:\Users\skotn_000\Desktop\WSELoader.exe
2015-08-13 10:48 - 2015-08-13 10:48 - 00000000 ____D C:\Users\skotn_000\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dropbox
2015-08-11 22:35 - 2015-08-11 22:35 - 00000000 ____D C:\Users\skotn_000\AppData\Local\MusicPlayer
2015-08-06 21:16 - 2015-08-27 21:14 - 00000000 ____D C:\Users\skotn_000\Downloads\Hry
2015-08-06 21:15 - 2015-08-21 22:52 - 00000000 ____D C:\Users\skotn_000\Downloads\Audioknihy
2015-08-06 21:06 - 2015-08-22 12:36 - 00000000 ____D C:\Users\skotn_000\Downloads\Filmy
2015-08-06 21:04 - 2015-08-06 21:04 - 00010240 ___SH C:\Users\skotn_000\Downloads\Thumbs.db
2015-08-04 13:13 - 2015-08-04 13:13 - 00000000 ____D C:\Users\skotn_000\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\0 A.D. alpha
2015-08-04 13:09 - 2015-08-04 13:09 - 00000000 ____D C:\Program Files (x86)\Microsoft XNA
2015-08-04 13:03 - 2015-08-04 13:13 - 00000000 ____D C:\Users\skotn_000\AppData\Local\0 A.D. alpha
==================== One Month Modified files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2015-08-30 16:06 - 2015-05-24 00:44 - 00000996 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskUserS-1-5-21-3338900602-571765566-1102821152-1002UA.job
2015-08-30 16:04 - 2015-06-08 16:35 - 01147373 _____ C:\WINDOWS\WindowsUpdate.log
2015-08-30 16:00 - 2012-07-26 10:12 - 00000000 ____D C:\WINDOWS\system32\sru
2015-08-30 15:49 - 2012-07-26 10:12 - 00000000 ____D C:\WINDOWS\AUInstallAgent
2015-08-30 06:09 - 2015-05-24 01:33 - 00000000 ____D C:\Users\skotn_000\AppData\Local\ClassicShell
2015-08-29 22:29 - 2015-05-24 01:23 - 00000000 ____D C:\Users\skotn_000\AppData\Roaming\Skype
2015-08-29 22:06 - 2015-05-24 00:44 - 00000944 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskUserS-1-5-21-3338900602-571765566-1102821152-1002Core.job
2015-08-29 22:01 - 2015-05-24 00:44 - 00003950 _____ C:\WINDOWS\System32\Tasks\GoogleUpdateTaskUserS-1-5-21-3338900602-571765566-1102821152-1002UA
2015-08-29 22:01 - 2015-05-24 00:44 - 00003570 _____ C:\WINDOWS\System32\Tasks\GoogleUpdateTaskUserS-1-5-21-3338900602-571765566-1102821152-1002Core
2015-08-29 21:46 - 2015-06-22 20:35 - 00000952 _____ C:\WINDOWS\Tasks\DropboxUpdateTaskUserS-1-5-21-3338900602-571765566-1102821152-1002UA.job
2015-08-29 21:44 - 2015-06-06 15:17 - 00000892 _____ C:\WINDOWS\Tasks\Adobe Flash Player PPAPI Notifier.job
2015-08-29 21:01 - 2012-07-26 10:12 - 00000000 ___HD C:\WINDOWS\ELAMBKUP
2015-08-29 19:50 - 2012-07-26 09:59 - 00000000 ____D C:\WINDOWS\CbsTemp
2015-08-29 18:49 - 2012-07-26 07:26 - 00262144 ___SH C:\WINDOWS\system32\config\ELAM
2015-08-29 18:33 - 2015-05-24 01:28 - 00000000 ____D C:\Program Files (x86)\Steam
2015-08-29 18:32 - 2015-05-24 20:53 - 00000000 ____D C:\Users\skotn_000\AppData\Roaming\TS3Client
2015-08-29 18:15 - 2012-07-26 09:22 - 00000006 ____H C:\WINDOWS\Tasks\SA.DAT
2015-08-29 18:13 - 2012-07-26 07:26 - 00262144 ___SH C:\WINDOWS\system32\config\BBI
2015-08-29 17:16 - 2015-05-24 00:38 - 00000000 ____D C:\ProgramData\AVAST Software
2015-08-29 16:46 - 2015-06-22 20:35 - 00000900 _____ C:\WINDOWS\Tasks\DropboxUpdateTaskUserS-1-5-21-3338900602-571765566-1102821152-1002Core.job
2015-08-28 20:23 - 2015-05-24 01:34 - 00000000 ____D C:\Program Files (x86)\Battle.net
2015-08-28 19:23 - 2015-05-24 01:34 - 00000000 ____D C:\Users\skotn_000\AppData\Local\Battle.net
2015-08-27 21:15 - 2013-07-15 21:43 - 00727488 _____ C:\WINDOWS\system32\perfh005.dat
2015-08-27 21:15 - 2013-07-15 21:43 - 00148006 _____ C:\WINDOWS\system32\perfc005.dat
2015-08-27 21:15 - 2012-07-26 09:28 - 01714430 _____ C:\WINDOWS\system32\PerfStringBackup.INI
2015-08-27 17:59 - 2015-06-08 16:54 - 00000000 ____D C:\Users\skotn_000\AppData\Roaming\vlc
2015-08-27 17:28 - 2015-05-24 01:31 - 00000000 ____D C:\Users\skotn_000\AppData\Roaming\uTorrent
2015-08-27 16:38 - 2015-06-09 21:06 - 00323072 ___SH C:\Users\skotn_000\Desktop\Thumbs.db
2015-08-27 16:10 - 2015-05-25 13:03 - 00000000 ____D C:\Users\skotn_000\AppData\Roaming\DAEMON Tools Lite
2015-08-26 22:52 - 2013-07-15 21:07 - 00000000 ____D C:\ProgramData\NVIDIA Corporation
2015-08-26 20:22 - 2015-05-24 01:29 - 00000000 ____D C:\Users\skotn_000\AppData\Local\Overwolf
2015-08-25 19:32 - 2015-05-24 01:32 - 00000000 ____D C:\Program Files (x86)\Overwolf
2015-08-25 11:18 - 2015-07-02 12:08 - 00000000 ____D C:\AdwCleaner
2015-08-21 21:55 - 2015-05-24 01:16 - 00003598 _____ C:\WINDOWS\System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-3338900602-571765566-1102821152-1002
2015-08-21 21:30 - 2015-05-31 11:13 - 00000000 ____D C:\Users\skotn_000\Documents\My Games
2015-08-21 20:42 - 2015-06-08 21:37 - 00000000 ____D C:\Program Files\Microsoft Office 15
2015-08-21 20:01 - 2015-05-24 01:12 - 00000000 ___RD C:\Users\skotn_000\Dropbox
2015-08-21 19:54 - 2015-06-22 20:34 - 00000000 ____D C:\Program Files (x86)\R.G. Mechanics
2015-08-21 18:26 - 2015-05-24 01:06 - 00000000 ____D C:\Users\skotn_000\AppData\Roaming\Dropbox
2015-08-21 13:00 - 2015-06-01 18:41 - 00000000 ____D C:\Users\skotn_000\Documents\stronghold crusader
2015-08-20 20:11 - 2015-05-24 01:29 - 00000000 ____D C:\Program Files\TeamSpeak 3 Client
2015-08-19 23:49 - 2015-07-11 13:08 - 00000000 ____D C:\Program Files (x86)\World of Warcraft
2015-08-19 23:28 - 2015-05-28 22:50 - 00000000 ____D C:\WINDOWS\Minidump
2015-08-19 23:11 - 2013-07-15 21:07 - 00000000 ____D C:\Program Files\NVIDIA Corporation
2015-08-19 23:11 - 2013-07-15 21:07 - 00000000 ____D C:\Program Files (x86)\NVIDIA Corporation
2015-08-19 23:08 - 2013-07-15 21:08 - 00000000 ____D C:\ProgramData\NVIDIA
2015-08-19 23:07 - 2012-07-26 10:12 - 00000000 ____D C:\WINDOWS\Help
2015-08-18 20:16 - 2015-05-25 13:52 - 00000000 ____D C:\Program Files (x86)\Hearthstone
2015-08-16 11:59 - 2012-07-26 10:12 - 00000000 ____D C:\WINDOWS\LiveKernelReports
2015-08-16 11:03 - 2015-05-24 01:22 - 00000000 ____D C:\ProgramData\Skype
2015-08-15 10:48 - 2015-05-24 17:46 - 00126464 _____ (Microsoft Corporation) C:\WINDOWS\system32\Robocopy.exe
2015-08-15 10:48 - 2015-05-24 17:46 - 00106496 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Robocopy.exe
2015-08-07 21:38 - 2015-06-13 14:42 - 00000000 ____D C:\Users\skotn_000\Documents\Telltale Games
2015-08-02 17:11 - 2015-07-06 23:58 - 00000000 ____D C:\Users\skotn_000\AppData\Local\Spotify
2015-08-02 15:42 - 2015-07-06 23:58 - 00000000 ____D C:\Users\skotn_000\AppData\Roaming\Spotify
==================== Files in the root of some directories =======
2015-05-27 21:49 - 2015-05-26 09:49 - 0000040 ____H () C:\Program Files (x86)\2e450ff3.tmp
2015-05-25 14:45 - 2015-06-22 00:00 - 0007602 _____ () C:\Users\skotn_000\AppData\Local\Resmon.ResmonCfg
2015-06-07 13:26 - 2015-06-07 13:26 - 0000000 ___SH () C:\ProgramData\.rdata
==================== Bamital & volsnap =================
(There is no automatic fix for files that do not pass verification.)
C:\WINDOWS\system32\winlogon.exe => File is digitally signed
C:\WINDOWS\system32\wininit.exe => MD5 is legit
C:\WINDOWS\explorer.exe => File is digitally signed
C:\WINDOWS\SysWOW64\explorer.exe => File is digitally signed
C:\WINDOWS\system32\svchost.exe => File is digitally signed
C:\WINDOWS\SysWOW64\svchost.exe => File is digitally signed
C:\WINDOWS\system32\services.exe => File is digitally signed
C:\WINDOWS\system32\User32.dll => File is digitally signed
C:\WINDOWS\SysWOW64\User32.dll => File is digitally signed
C:\WINDOWS\system32\userinit.exe => MD5 is legit
C:\WINDOWS\SysWOW64\userinit.exe => MD5 is legit
C:\WINDOWS\system32\rpcss.dll => MD5 is legit
C:\WINDOWS\system32\dnsapi.dll => File is digitally signed
C:\WINDOWS\SysWOW64\dnsapi.dll => File is digitally signed
C:\WINDOWS\system32\Drivers\volsnap.sys => File is digitally signed
===***===***===***=== Extract of Additional scan result of Farbar Recovery Scan Tool ===***===***===***===
==================== Drive and Memory info ===================
==================== MBR and Partition Table ==================
==================== Scheduled Tasks (whitelisted) ==================
(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)
Task: C:\WINDOWS\Tasks\Adobe Flash Player PPAPI Notifier.job => C:\WINDOWS\SysWOW64\Macromed\Flash\FlashUtil32_18_0_0_203_pepper.exe
Task: C:\WINDOWS\Tasks\DropboxUpdateTaskUserS-1-5-21-3338900602-571765566-1102821152-1002Core.job => C:\Users\skotn_000\AppData\Local\Dropbox\Update\DropboxUpdate.exe
Task: C:\WINDOWS\Tasks\DropboxUpdateTaskUserS-1-5-21-3338900602-571765566-1102821152-1002UA.job => C:\Users\skotn_000\AppData\Local\Dropbox\Update\DropboxUpdate.exe
Task: C:\WINDOWS\Tasks\GoogleUpdateTaskUserS-1-5-21-3338900602-571765566-1102821152-1002Core.job => C:\Users\skotn_000\AppData\Local\Google\Update\GoogleUpdate.exe
Task: C:\WINDOWS\Tasks\GoogleUpdateTaskUserS-1-5-21-3338900602-571765566-1102821152-1002UA.job => C:\Users\skotn_000\AppData\Local\Google\Update\GoogleUpdate.exe
==================== Alternate Data Streams (whitelisted) ==================
==================== Security Center ==================
AV: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AV: avast! Antivirus (Disabled - Up to date) {17AD7D40-BA12-9C46-7131-94903A54AD8B}
AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: Spybot - Search and Destroy (Disabled - Out of date) {9BC38DF1-3CCA-732D-A930-C1CA5F20A4B0}
AS: avast! Antivirus (Disabled - Up to date) {ACCC9CA4-9C28-93C8-4B81-AFE241D3E736}
===***===***===***=== Supplementary Scan createdy by FRSTLauncher ===***===***===***===
Posledni aktualizace FRSTLauncheru: 25_11_2013 (01)
Posledni aktualizace Modifikacniho skriptu: 30_09_2013 (01)
***** Velikost "Plochy" *****
Velikost slozky "C:\Users\skotn_000\Desktop" je 29 MB.
***** Startup Programs *****
***** Firewall rules *****
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
EnableFirewall REG_DWORD 0x1
DisableNotifications REG_DWORD 0x0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
EnableFirewall REG_DWORD 0x1
DisableNotifications REG_DWORD 0x0
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"C:\\Program Files (x86)\\Spybot - Search & Destroy 2\\SDTray.exe"="C:\\Program Files (x86)\\Spybot - Search & Destroy 2\\SDTray.exe:*:Enabled:Spybot - Search & Destroy tray access"
"C:\\Program Files (x86)\\Spybot - Search & Destroy 2\\SDFSSvc.exe"="C:\\Program Files (x86)\\Spybot - Search & Destroy 2\\SDFSSvc.exe:*:Enabled:Spybot-S&D 2 Scanner Service"
"C:\\Program Files (x86)\\Spybot - Search & Destroy 2\\SDUpdate.exe"="C:\\Program Files (x86)\\Spybot - Search & Destroy 2\\SDUpdate.exe:*:Enabled:Spybot-S&D 2 Updater"
"C:\\Program Files (x86)\\Spybot - Search & Destroy 2\\SDUpdSvc.exe"="C:\\Program Files (x86)\\Spybot - Search & Destroy 2\\SDUpdSvc.exe:*:Enabled:Spybot-S&D 2 Background update service"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
***** System Restore *****
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"Generalize_DisableSR"=dword:00000000
==================== End Of Log ==============================