Vyskakují reklamy
Napsal: 02 říj 2015 18:31
Prosím o pomoc
Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version:30-09-2015
Ran by Owner (administrator) on LENOVO-PC (02-10-2015 19:22:16)
Running from C:\Users\Owner\Desktop
Loaded Profiles: Owner (Available Profiles: Owner)
Platform: Windows 8.1 (X64) Language: Čeština (Česká republika)
Internet Explorer Version 11 (Default browser: FF)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/33 ... scan-tool/
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(AMD) C:\Windows\System32\atiesrxx.exe
(Microsoft Corporation) C:\Windows\System32\wlanext.exe
(Advanced Micro Devices, Inc.) C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe
() C:\Program Files (x86)\Realtek\Realtek Bluetooth\BTDevMgr.exe
(Conexant Systems Inc.) C:\Windows\System32\CxAudMsg64.exe
(LENOVO INCORPORATED.) C:\Program Files\Lenovo\iMController\SystemAgentService.exe
(Lenovo(beijing) Limited) C:\Windows\System32\LenovoWiFiHotspotSvr.exe
(Lenovo(beijing) Limited) C:\Program Files (x86)\Lenovo\Lenovo Updates\LUService.exe
(Lenovo) C:\Program Files\Lenovo PhoneCompanion\PhoneCompanionPusher.exe
() C:\Program Files\CyberLink\Shared files\RichVideo64.exe
(Conexant Systems, Inc.) C:\Windows\SysWOW64\SASrv.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnhService.exe
() C:\Program Files (x86)\Lenovo\Lenovo VeriFace Pro\VfConnectorService.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\MsMpEng.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\NisSrv.exe
() C:\Program Files\Lenovo PhoneCompanion\adb.exe
(AMD) C:\Windows\System32\atieclxx.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
(IvoSoft) C:\Program Files\Classic Shell\ClassicStartMenu.exe
(Realtek Semiconductor Corporation) C:\Program Files (x86)\Realtek\Realtek Bluetooth\BTServer.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
(Conexant Systems, Inc.) C:\Program Files\CONEXANT\cAudioFilterAgent\CAudioFilterAgent64.exe
() C:\Program Files\CONEXANT\ForteConfig\fmapp.exe
(Realtek semiconductor) C:\Windows\RTFTrack.exe
(Lenovo) C:\Program Files\Lenovo\Onekey Theater\OnekeyStudio.exe
(Lenovo) C:\Program Files\Lenovo PhoneCompanion\Phone Companion.exe
(Microsoft Corporation) C:\Windows\System32\GWX\GWX.exe
(Lenovo(beijing) Limited) C:\Program Files (x86)\Lenovo\Energy Manager\Energy Manager.exe
(Lenovo(beijing) Limited) C:\Program Files (x86)\Lenovo\Energy Manager\utility.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(McAfee, Inc.) C:\Program Files\McAfee Security Scan\3.11.163\SSScheduler.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(CyberLink Corp.) C:\Program Files (x86)\Lenovo\PowerDVD10\PDVD10Serv.exe
() C:\Program Files (x86)\DNS Unlocker\dnsseadrift.exe
(Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe
(Adobe Systems Incorporated) C:\Windows\System32\Macromed\Flash\FlashUtil_ActiveX.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\MpCmdRun.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
==================== Registry (Whitelisted) ===========================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [cAudioFilterAgent] => C:\Program Files\Conexant\cAudioFilterAgent\cAudioFilterAgent64.exe [907480 2013-09-05] (Conexant Systems, Inc.)
HKLM\...\Run: [ForteConfig] => C:\Program Files\Conexant\ForteConfig\fmapp.exe [49056 2010-10-26] ()
HKLM\...\Run: [SmartAudio] => C:\Program Files\CONEXANT\SAII\SACpl.exe [1647616 2012-06-13] (Conexant Systems, Inc.)
HKLM\...\Run: [SynTPEnh] => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2808560 2014-06-25] (Synaptics Incorporated)
HKLM\...\Run: [BtServer] => C:\Program Files (x86)\REALTEK\Realtek Bluetooth\BTServer.exe [216064 2014-01-06] (Realtek Semiconductor Corporation)
HKLM\...\Run: [RtsFT] => C:\windows\RTFTrack.exe [6340312 2014-01-21] (Realtek semiconductor)
HKLM\...\Run: [OnekeyStudio] => C:\Program Files\Lenovo\Onekey Theater\OnekeyStudio.exe [4196432 2012-09-15] (Lenovo)
HKLM\...\Run: [PhoneCompanion] => C:\Program Files\Lenovo PhoneCompanion\Phone Companion.exe [836592 2014-09-16] (Lenovo)
HKLM\...\Run: [Energy Manager] => C:\Program Files (x86)\Lenovo\Energy Manager\Energy Manager.exe [16094704 2014-09-16] (Lenovo(beijing) Limited)
HKLM\...\Run: [Lenovo Utility] => C:\Program Files (x86)\Lenovo\Energy Manager\Utility.exe [10842096 2014-09-16] (Lenovo(beijing) Limited)
HKLM\...\Run: [Classic Start Menu] => C:\Program Files\Classic Shell\ClassicStartMenu.exe [161984 2014-04-20] (IvoSoft)
HKLM-x32\...\Run: [StartCCC] => C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\amd64\CLIStart.exe [767200 2014-06-25] (Advanced Micro Devices, Inc.)
HKLM-x32\...\Run: [UpdateP2GShortCut] => C:\Program Files (x86)\Lenovo\Power2Go\MUITransfer\MUIStartMenu.exe [214312 2011-12-07] (CyberLink Corp.)
HKLM-x32\...\Run: [mncwvwsfSrv] => C:\windows\SysWOW64\mncwvwsf.vbe [7670 2014-03-05] ()
HKLM-x32\...\Run: [NtVdmSrv] => C:\windows\inf\ntvdm.vbe
HKLM-x32\...\Run: [MSStp] => C:\windows\inf\msstp.vbe [1584 2014-03-05] ()
HKLM-x32\...\Run: [mncjxdjSrv] => C:\windows\SysWOW64\mncjxdj.vbe [7670 2014-03-05] ()
HKU\S-1-5-21-4198438056-3133198569-554230774-1002\...\Run: [GoogleChromeAutoLaunch_721577D41E77D440C916E2687EBA0267] => C:\Program Files (x86)\Google\Chrome\Application\chrome.exe [813896 2015-07-07] (Google Inc.)
HKU\S-1-5-21-4198438056-3133198569-554230774-1002\...\MountPoints2: {f7bfb0cc-fe25-11e4-827c-38b1db5ead96} - "F:\Startme.exe"
ShellIconOverlayIdentifiers: [00001LenovoSyncComplete] -> {1E9CED2C-E7B4-4C47-B07A-25416393B67B} => C:\Program Files\Hightail\Hightail for Lenovo\YSINSE64.dll [2014-06-23] (Hightail Inc.)
ShellIconOverlayIdentifiers: [00002LenovoSyncActive] -> {C1285F4D-918F-4EF2-BC94-CAD5B118C835} => C:\Program Files\Hightail\Hightail for Lenovo\YSINSE64.dll [2014-06-23] (Hightail Inc.)
ShellIconOverlayIdentifiers: [00003LenovoSyncError] -> {CE5633DA-1488-4D1D-9A9B-B500297D4A8C} => C:\Program Files\Hightail\Hightail for Lenovo\YSINSE64.dll [2014-06-23] (Hightail Inc.)
ShellIconOverlayIdentifiers: [00004LenovoLocalOnly] -> {C7362DA9-D3AC-4C17-B2F5-2F1823FA04C3} => C:\Program Files\Hightail\Hightail for Lenovo\YSINSE64.dll [2014-06-23] (Hightail Inc.)
ShellIconOverlayIdentifiers-x32: [00001LenovoSyncComplete] -> {1E9CED2C-E7B4-4C47-B07A-25416393B67B} => C:\Program Files (x86)\Hightail\Hightail for Lenovo\YSINSE.dll [2014-06-23] (Hightail Inc.)
ShellIconOverlayIdentifiers-x32: [00002LenovoSyncActive] -> {C1285F4D-918F-4EF2-BC94-CAD5B118C835} => C:\Program Files (x86)\Hightail\Hightail for Lenovo\YSINSE.dll [2014-06-23] (Hightail Inc.)
ShellIconOverlayIdentifiers-x32: [00003LenovoSyncError] -> {CE5633DA-1488-4D1D-9A9B-B500297D4A8C} => C:\Program Files (x86)\Hightail\Hightail for Lenovo\YSINSE.dll [2014-06-23] (Hightail Inc.)
ShellIconOverlayIdentifiers-x32: [00004LenovoLocalOnly] -> {C7362DA9-D3AC-4C17-B2F5-2F1823FA04C3} => C:\Program Files (x86)\Hightail\Hightail for Lenovo\YSINSE.dll [2014-06-23] (Hightail Inc.)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\McAfee Security Scan Plus.lnk [2014-12-25]
ShortcutTarget: McAfee Security Scan Plus.lnk -> C:\Program Files\McAfee Security Scan\3.11.163\SSScheduler.exe (McAfee, Inc.)
CHR HKLM\SOFTWARE\Policies\Google: Restriction <======= ATTENTION
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
Hosts: 0.0.0.1 mssplus.mcafee.com
Tcpip\Parameters: [DhcpNameServer] 10.0.0.138
Tcpip\..\Interfaces\{0826528E-6122-4F77-92A1-CCF0A846CB33}: [NameServer] 82.163.143.172,82.163.142.174
Tcpip\..\Interfaces\{0826528E-6122-4F77-92A1-CCF0A846CB33}: [DhcpNameServer] 10.0.0.138
Tcpip\..\Interfaces\{A67282DE-1FD5-4F0A-9F44-5488AA98A3E8}: [DhcpNameServer] 192.168.2.1
Internet Explorer:
==================
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.msn.com/?pc=MSE1
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.msn.com/?pc=MSE1
HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.mystartsearch.com/web/?type=ds&ts=1 ... earchTerms}
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.mystartsearch.com/web/?type=ds&ts=1 ... earchTerms}
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.mystartsearch.com/?type=hp&ts=14242 ... X84GXT3EAT
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.mystartsearch.com/?type=hp&ts=14242 ... X84GXT3EAT
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://www.mystartsearch.com/web/?type=ds&ts=1 ... earchTerms}
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://www.mystartsearch.com/web/?type=ds&ts=1 ... earchTerms}
HKU\S-1-5-21-4198438056-3133198569-554230774-1002\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.msn.com/?pc=MSE1
HKU\S-1-5-21-4198438056-3133198569-554230774-1002\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.mystartsearch.com/?type=hp&ts=14242 ... X84GXT3EAT
HKU\S-1-5-21-4198438056-3133198569-554230774-1002\Software\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = hxxp://www.lenovo.com
SearchScopes: HKLM -> DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = hxxp://www.bing.com/search?q={searchTerms}&form=MSSEDF&pc=MSE1
SearchScopes: HKLM -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKLM -> {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = hxxp://www.bing.com/search?q={searchTerms}&form=MSSEDF&pc=MSE1
SearchScopes: HKLM-x32 -> DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = hxxp://www.bing.com/search?q={searchTerms}&form=MSSEDF&pc=MSE1
SearchScopes: HKLM-x32 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKLM-x32 -> {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = hxxp://www.bing.com/search?q={searchTerms}&form=MSSEDF&pc=MSE1
SearchScopes: HKU\S-1-5-21-4198438056-3133198569-554230774-1002 -> {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = hxxp://www.mystartsearch.com/web/?type=ds&ts=1 ... earchTerms}
FireFox:
========
FF ProfilePath: C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\fyl0t5bl.default-1437126649091
FF Plugin: @adobe.com/FlashPlayer -> C:\windows\system32\Macromed\Flash\NPSWF64_19_0_0_185.dll [2015-09-22] ()
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\windows\SysWOW64\Macromed\Flash\NPSWF32_19_0_0_185.dll [2015-09-22] ()
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.27.5\npGoogleUpdate3.dll [2015-06-16] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.27.5\npGoogleUpdate3.dll [2015-06-16] (Google Inc.)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll [2015-06-29] (Adobe Systems Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\np-mswmp.dll [2007-04-10] (Microsoft Corporation)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\nppdf32.dll [2015-06-29] (Adobe Systems Inc.)
FF Extension: SSAveerExtensioon - C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\fyl0t5bl.default-1437126649091\Extensions\AnE@S.com [2015-08-07]
FF Extension: The AdBlocker - C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\fyl0t5bl.default-1437126649091\Extensions\chdrdfoofd_fvdef@qrdkdqnymijvofby.com [2015-08-31]
FF Extension: RoboSaiver - C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\fyl0t5bl.default-1437126649091\Extensions\f5zJ@N.net [2015-08-26]
FF Extension: BBitSaVer - C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\fyl0t5bl.default-1437126649091\Extensions\oLG@4U1E.net [2015-08-03]
FF HKLM-x32\...\Firefox\Extensions: [searchengine@gmail.com] - C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\b9l3tw00.default\extensions\searchengine@gmail.com => not found
Chrome:
=======
CHR dev: Chrome dev build detected! <======= ATTENTION
CHR StartupUrls: Default -> "hxxp://search.gboxapp.com/"
CHR Profile: C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (Prezentace Google) - C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2015-06-16]
CHR Extension: (Wise Ads Block) - C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\alcmakjhknigccfidaelkafjmfifkhkc [2015-08-26]
CHR Extension: (Dokumenty Google) - C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2015-06-16]
CHR Extension: (Disk Google) - C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2015-06-16]
CHR Extension: (YouTube) - C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2015-06-16]
CHR Extension: (Vyhledávání Google) - C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2015-06-16]
CHR Extension: (Tabulky Google) - C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2015-06-16]
CHR Extension: (Platby Internetového obchodu Chrome) - C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2015-06-16]
CHR Extension: (Gmail) - C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2015-06-16]
==================== Services (Whitelisted) ========================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R2 AMD FUEL Service; C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe [344064 2014-06-25] (Advanced Micro Devices, Inc.) [File not signed]
R2 BTDevManager; C:\Program Files (x86)\REALTEK\Realtek Bluetooth\BTDevMgr.exe [84992 2014-01-22] () [File not signed]
S3 Lenovo EasyPlus Hotspot; C:\Program Files (x86)\Common Files\lenovo\easyplussdk\bin\EPHotspot64.exe [533760 2014-06-03] (Lenovo)
R2 Lenovo System Agent Service; C:\Program Files\Lenovo\iMController\SystemAgentService.exe [584960 2014-05-22] (LENOVO INCORPORATED.)
R2 LenovoWiFiHotspotSvr; C:\Windows\System32\LenovoWiFiHotspotSvr.exe [198192 2014-09-16] (Lenovo(beijing) Limited)
R2 LUService; C:\Program Files (x86)\Lenovo\Lenovo Updates\LUService.exe [38896 2014-02-18] (Lenovo(beijing) Limited)
S3 McComponentHostService; C:\Program Files\McAfee Security Scan\3.11.163\McCHSvc.exe [289256 2015-07-31] (McAfee, Inc.)
R2 PhoneCompanionPusher; C:\Program Files\Lenovo PhoneCompanion\PhoneCompanionPusher.exe [288240 2014-09-16] (Lenovo)
S3 PhoneCompanionVap; C:\Program Files\Lenovo PhoneCompanion\PhoneCompanionVap.exe [308720 2014-09-16] (Lenovo)
R2 RichVideo64; C:\Program Files\CyberLink\Shared files\RichVideo64.exe [390632 2012-04-25] ()
R2 SynTPEnhService; C:\Program Files\Synaptics\SynTP\SynTPEnhService.exe [190704 2014-06-25] (Synaptics Incorporated)
R2 VeriFaceSrv; C:\Program Files (x86)\Lenovo\Lenovo VeriFace Pro\VfConnectorService.exe [68880 2014-09-16] ()
R3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [366520 2015-02-04] (Microsoft Corporation)
R2 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [23792 2015-02-04] (Microsoft Corporation)
S2 gupdate; "C:\Program Files (x86)\Google\Update\GoogleUpdate.exe" /svc [X]
S3 gupdatem; "C:\Program Files (x86)\Google\Update\GoogleUpdate.exe" /medsvc [X]
S2 ReimageRealTimeProtector; C:\Program Files\Reimage\Reimage Protector\ReiGuard.exe [X]
S3 TrustedInstaller; %SystemRoot%\servicing\TrustedInstaller.exe [X]
===================== Drivers (Whitelisted) ==========================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R0 amdkmpfd; C:\Windows\System32\drivers\amdkmpfd.sys [36608 2013-12-14] (Advanced Micro Devices, Inc.)
R2 AODDriver4.3; C:\Program Files\ATI Technologies\ATI.ACE\Fuel\amd64\AODDriver2.sys [59616 2014-02-12] (Advanced Micro Devices)
R2 APXACC; C:\Windows\system32\DRIVERS\appexDrv.sys [225504 2014-03-28] (AppEx Networks Corporation)
R3 AtiHDAudioService; C:\Windows\system32\drivers\AtihdWB6.sys [222720 2014-03-12] (Advanced Micro Devices)
R3 BthLEEnum; C:\Windows\system32\DRIVERS\BthLEEnum.sys [226304 2014-03-18] (Microsoft Corporation)
S0 ebdrv; C:\Windows\System32\drivers\evbda.sys [3357024 2013-08-22] (Broadcom Corporation)
S3 NETwNe64; C:\Windows\system32\DRIVERS\NETwew02.sys [4649440 2013-06-18] (Intel Corporation)
R3 RtkBtFilter; C:\Windows\system32\DRIVERS\RtkBtfilter.sys [558296 2014-04-12] (Realtek Semiconductor Corporation)
R3 rtsuvc; C:\Windows\system32\DRIVERS\rtsuvc.sys [9105624 2014-01-21] (Realtek Semiconductor Corp.)
R3 RTWlanE; C:\Windows\system32\DRIVERS\rtwlane.sys [3410136 2014-04-11] (Realtek Semiconductor Corporation )
S0 WdBoot; C:\Windows\System32\drivers\WdBoot.sys [44024 2015-02-04] (Microsoft Corporation)
R0 WdFilter; C:\Windows\System32\drivers\WdFilter.sys [264000 2015-02-04] (Microsoft Corporation)
R3 WdNisDrv; C:\Windows\System32\Drivers\WdNisDrv.sys [114496 2015-02-04] (Microsoft Corporation)
S3 wsvd; C:\Windows\system32\DRIVERS\wsvd.sys [102376 2012-06-14] ("CyberLink)
S1 atshpnjq; \??\C:\windows\system32\drivers\atshpnjq.sys [X]
S1 awfztrnp; \??\C:\windows\system32\drivers\awfztrnp.sys [X]
S1 bgtgmhvu; \??\C:\windows\system32\drivers\bgtgmhvu.sys [X]
S1 ivtahkky; \??\C:\windows\system32\drivers\ivtahkky.sys [X]
==================== NetSvcs (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
==================== One Month Created files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2015-10-02 19:22 - 2015-10-02 19:22 - 00019038 _____ C:\Users\Owner\Desktop\FRST.txt
2015-10-02 19:20 - 2015-10-02 19:22 - 00000000 ____D C:\FRST
2015-10-02 19:20 - 2015-10-02 19:20 - 02192384 _____ (Farbar) C:\Users\Owner\Desktop\FRST64.exe
2015-10-02 19:19 - 2015-10-02 19:19 - 00112640 _____ (forum.viry.cz) C:\Users\Owner\Desktop\FRSTLauncher.exe
2015-10-02 19:19 - 2015-10-02 19:19 - 00015327 _____ C:\Users\Owner\Desktop\LM.bat
2015-10-02 19:16 - 2015-10-02 19:19 - 00029696 _____ C:\Users\Owner\AppData\Local\MSGBOX.EXE
2015-09-27 17:09 - 2015-05-10 18:38 - 06669238 _____ C:\Users\Owner\Downloads\Kabát---Brousíme-nože---PROMO-SINGL---2015-(256kbit).m4a
2015-09-27 16:47 - 2015-09-27 17:06 - 326094085 _____ C:\Users\Owner\Downloads\100-Wiz-Khalifa-&-Iggy-Azalea---Go-Hard-Or-Go-Home.rar
2015-09-26 15:05 - 2015-09-26 15:05 - 00026356 _____ C:\windows\System32\Tasks\DNSSEADRIFT
2015-09-26 15:05 - 2015-09-26 15:05 - 00000000 ____D C:\Program Files (x86)\DNS Unlocker
2015-09-21 13:41 - 2015-09-21 13:49 - 00000000 ____D C:\Users\Owner\Downloads\hiphop
2015-09-19 17:22 - 2015-10-01 18:07 - 00001279 _____ C:\Users\Owner\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Wi-FiHotspotChgToast.lnk
2015-09-19 17:18 - 2015-09-19 17:27 - 00000000 ____D C:\Users\Owner\Desktop\EDM
2015-09-03 20:09 - 2015-09-03 20:09 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\McAfee Security Scan Plus
2015-09-03 20:09 - 2015-09-03 20:09 - 00000000 ____D C:\Program Files\McAfee Security Scan
==================== One Month Modified files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2015-10-02 19:22 - 2014-12-09 06:03 - 00003596 _____ C:\windows\System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-4198438056-3133198569-554230774-1002
2015-10-02 19:17 - 2014-12-09 06:30 - 00000000 ____D C:\Users\Owner\AppData\Roaming\ClassicShell
2015-10-02 19:17 - 2014-12-09 05:57 - 01267941 _____ C:\Users\Owner\AppData\Local\BTServer.log
2015-10-02 19:01 - 2014-09-16 02:55 - 01694514 _____ C:\windows\WindowsUpdate.log
2015-10-02 19:00 - 2013-08-22 17:36 - 00000000 ____D C:\windows\system32\sru
2015-10-02 18:49 - 2014-12-09 06:22 - 00000914 _____ C:\windows\Tasks\Adobe Flash Player Updater.job
2015-10-02 18:43 - 2015-01-25 22:32 - 00000479 _____ C:\Users\Owner\rgut
2015-10-02 18:42 - 2014-09-16 03:35 - 00739924 _____ C:\windows\system32\perfh005.dat
2015-10-02 18:42 - 2014-09-16 03:35 - 00151610 _____ C:\windows\system32\perfc005.dat
2015-10-02 18:42 - 2014-03-18 11:53 - 01745984 _____ C:\windows\system32\PerfStringBackup.INI
2015-10-02 17:16 - 2014-09-16 03:32 - 08680212 _____ C:\Users\Public\CAFADEBUG.log
2015-10-02 15:05 - 2015-08-15 03:05 - 00000360 _____ C:\windows\Tasks\Bidaily Synchronize Task[8da6].job
2015-10-02 13:57 - 2014-12-09 06:09 - 00003974 _____ C:\windows\System32\Tasks\User_Feed_Synchronization-{118BDF86-4DAF-493B-BB27-91CAA24A69C7}
2015-10-01 18:07 - 2014-09-16 04:38 - 00000000 ____D C:\ProgramData\LU
2015-10-01 17:35 - 2013-08-22 16:46 - 00050003 _____ C:\windows\setupact.log
2015-10-01 17:35 - 2013-08-22 16:45 - 00000006 ____H C:\windows\Tasks\SA.DAT
2015-10-01 17:34 - 2014-09-16 04:15 - 00006656 _____ C:\windows\system32\VfService.trf
2015-10-01 17:34 - 2014-09-16 03:27 - 00065536 _____ C:\windows\system32\spu_storage.bin
2015-10-01 17:34 - 2013-08-22 15:25 - 00262144 ___SH C:\windows\system32\config\BBI
2015-09-29 11:51 - 2015-08-06 21:58 - 00000000 ____D C:\Program Files (x86)\SaVerExxtensionn
2015-09-26 10:09 - 2013-08-22 17:36 - 00000000 ____D C:\windows\AppReadiness
2015-09-22 19:49 - 2014-12-09 06:22 - 00003802 _____ C:\windows\System32\Tasks\Adobe Flash Player Updater
2015-09-20 11:20 - 2015-08-26 10:52 - 00000000 ____D C:\Program Files (x86)\RoBoSAver
2015-09-20 07:12 - 2015-08-26 10:55 - 00000000 ____D C:\Program Files (x86)\Wise Ads Block
2015-09-20 07:11 - 2015-08-12 08:44 - 00000000 ____D C:\Program Files (x86)\BestaSaveFourYou
2015-09-20 07:11 - 2015-08-03 15:49 - 00000000 ____D C:\Program Files (x86)\BitSoaver
2015-09-20 07:11 - 2015-08-03 15:48 - 00000000 ____D C:\Program Files (x86)\BBitSaVer
2015-09-20 07:11 - 2015-08-03 07:21 - 00000000 ____D C:\Program Files (x86)\AntiPorn Pro The best AntiPorn addon
2015-09-20 07:10 - 2015-08-06 22:00 - 00000000 ____D C:\Program Files (x86)\My IP address
2015-09-20 07:10 - 2015-08-03 15:48 - 00000000 ____D C:\Program Files (x86)\QR Code Maker and Decoder
2015-09-20 07:10 - 2015-08-03 07:22 - 00000000 ____D C:\Program Files (x86)\RanndomPricE
2015-09-20 07:10 - 2015-08-03 07:22 - 00000000 ____D C:\Program Files (x86)\RaandomPrIce
2015-09-20 07:10 - 2015-08-03 07:21 - 00000000 ____D C:\Program Files (x86)\RanedOOmPRiCE
2015-09-20 07:09 - 2015-06-05 09:38 - 00000000 ____D C:\Program Files (x86)\SAveLOts
2015-09-20 07:09 - 2015-06-05 09:38 - 00000000 ____D C:\Program Files (x86)\SaveeLotss
2015-09-20 07:09 - 2015-06-05 09:37 - 00000000 ____D C:\Program Files (x86)\SaveaLottss
2015-09-20 07:09 - 2015-04-26 14:01 - 00000000 ____D C:\Program Files (x86)\sound on click
2015-09-20 07:08 - 2015-08-06 22:00 - 00000000 ____D C:\Program Files (x86)\SSAveerExtensioon
2015-09-20 07:08 - 2015-02-18 14:26 - 00000000 ____D C:\Program Files (x86)\UUniDealeS e
2015-09-20 07:02 - 2015-05-17 13:06 - 00000000 ____D C:\Program Files (x86)\Epic Soccer Barcelona
2015-09-20 07:01 - 2015-06-05 18:24 - 00000000 ____D C:\Program Files (x86)\SickBeardConnect
2015-09-20 07:01 - 2015-05-17 13:06 - 00000000 ____D C:\Program Files (x86)\ShoPDrop
2015-09-20 07:01 - 2015-05-17 13:06 - 00000000 ____D C:\Program Files (x86)\RegularoDealS
2015-09-20 07:01 - 2015-02-18 14:27 - 00000000 ____D C:\Program Files (x86)\UniDeals
2015-09-20 06:57 - 2015-08-26 10:51 - 00000000 ____D C:\Program Files (x86)\RoboSaiver
2015-09-20 06:57 - 2015-04-26 14:02 - 00000000 ____D C:\Program Files (x86)\CheeapMe
2015-09-20 06:57 - 2015-02-18 14:27 - 00000000 ____D C:\Program Files (x86)\Hearthstone Stream Browser
2015-09-20 06:55 - 2015-06-11 21:36 - 00000000 ____D C:\Program Files (x86)\MicrOOMaSteers
2015-09-19 17:12 - 2014-12-09 05:56 - 00000000 ____D C:\Users\Owner
2015-09-19 17:11 - 2015-04-04 23:50 - 00000000 ___SD C:\windows\system32\GWX
2015-09-19 17:10 - 2014-12-25 18:48 - 00000000 ____D C:\ProgramData\McAfee Security Scan
2015-09-19 17:10 - 2014-12-09 06:21 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2015-09-19 17:10 - 2014-12-09 05:58 - 00000000 ____D C:\Users\Owner\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Lenovo
2015-09-19 17:04 - 2013-08-22 17:36 - 00000000 ____D C:\windows\registration
2015-09-19 17:03 - 2015-06-16 10:28 - 00000000 ____D C:\Users\Owner\AppData\Local\Google
2015-09-15 08:31 - 2014-03-18 11:44 - 00019736 _____ C:\windows\PFRO.log
2015-09-09 15:28 - 2015-08-03 15:48 - 00000000 ____D C:\Program Files (x86)\BitSaveur
2015-09-09 15:28 - 2015-06-12 07:26 - 00000000 ____D C:\Program Files (x86)\TakeTHeCoupon
2015-09-09 15:28 - 2015-04-29 14:55 - 00000000 ____D C:\Program Files (x86)\BeesTSaveForYYoue
2015-09-09 15:26 - 2015-05-17 13:05 - 00000000 ____D C:\Program Files (x86)\FunDEalSS
2015-09-03 20:09 - 2014-12-25 18:48 - 00001961 _____ C:\Users\Public\Desktop\McAfee Security Scan Plus.lnk
==================== Files in the root of some directories =======
2015-04-17 13:11 - 2015-08-06 21:59 - 0000079 _____ () C:\Program Files (x86)\prefs.js
2015-07-08 19:32 - 2015-08-17 22:32 - 0000020 _____ () C:\Users\Owner\AppData\Roaming\appdataFr2.bin
2015-07-15 15:37 - 2015-08-14 18:38 - 0000024 _____ () C:\Users\Owner\AppData\Roaming\appdataFr25.bin
2014-12-09 06:19 - 2015-08-23 16:01 - 0000421 _____ () C:\Users\Owner\AppData\Roaming\burnaware.ini
2014-12-09 05:57 - 2015-10-02 19:17 - 1267941 _____ () C:\Users\Owner\AppData\Local\BTServer.log
2015-08-20 09:50 - 2015-08-20 09:50 - 0000031 _____ () C:\Users\Owner\AppData\Local\burnaware.ini
2015-10-02 19:16 - 2015-10-02 19:19 - 0029696 _____ () C:\Users\Owner\AppData\Local\MSGBOX.EXE
2015-03-12 08:17 - 2015-03-12 08:17 - 0000017 _____ () C:\Users\Owner\AppData\Local\resmon.resmoncfg
2014-09-16 03:32 - 2014-09-16 03:32 - 0000000 ____H () C:\ProgramData\DP45977C.lfl
Some files in TEMP:
====================
C:\Users\Owner\AppData\Local\Temp\supoptsetup.exe
C:\Users\Owner\AppData\Local\Temp\_unps.exe
==================== Bamital & volsnap =================
(There is no automatic fix for files that do not pass verification.)
C:\windows\system32\winlogon.exe => File is digitally signed
C:\windows\system32\wininit.exe => File is digitally signed
C:\windows\explorer.exe => File is digitally signed
C:\windows\SysWOW64\explorer.exe => File is digitally signed
C:\windows\system32\svchost.exe => File is digitally signed
C:\windows\SysWOW64\svchost.exe => File is digitally signed
C:\windows\system32\services.exe => File is digitally signed
C:\windows\system32\User32.dll => File is digitally signed
C:\windows\SysWOW64\User32.dll => File is digitally signed
C:\windows\system32\userinit.exe => File is digitally signed
C:\windows\SysWOW64\userinit.exe => File is digitally signed
C:\windows\system32\rpcss.dll => File is digitally signed
C:\windows\system32\dnsapi.dll => File is digitally signed
C:\windows\SysWOW64\dnsapi.dll => File is digitally signed
C:\windows\system32\Drivers\volsnap.sys => File is digitally signed
LastRegBack: 2015-09-29 11:34
==================== End of FRST.txt ============================
Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version:30-09-2015
Ran by Owner (administrator) on LENOVO-PC (02-10-2015 19:22:16)
Running from C:\Users\Owner\Desktop
Loaded Profiles: Owner (Available Profiles: Owner)
Platform: Windows 8.1 (X64) Language: Čeština (Česká republika)
Internet Explorer Version 11 (Default browser: FF)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/33 ... scan-tool/
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(AMD) C:\Windows\System32\atiesrxx.exe
(Microsoft Corporation) C:\Windows\System32\wlanext.exe
(Advanced Micro Devices, Inc.) C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe
() C:\Program Files (x86)\Realtek\Realtek Bluetooth\BTDevMgr.exe
(Conexant Systems Inc.) C:\Windows\System32\CxAudMsg64.exe
(LENOVO INCORPORATED.) C:\Program Files\Lenovo\iMController\SystemAgentService.exe
(Lenovo(beijing) Limited) C:\Windows\System32\LenovoWiFiHotspotSvr.exe
(Lenovo(beijing) Limited) C:\Program Files (x86)\Lenovo\Lenovo Updates\LUService.exe
(Lenovo) C:\Program Files\Lenovo PhoneCompanion\PhoneCompanionPusher.exe
() C:\Program Files\CyberLink\Shared files\RichVideo64.exe
(Conexant Systems, Inc.) C:\Windows\SysWOW64\SASrv.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnhService.exe
() C:\Program Files (x86)\Lenovo\Lenovo VeriFace Pro\VfConnectorService.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\MsMpEng.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\NisSrv.exe
() C:\Program Files\Lenovo PhoneCompanion\adb.exe
(AMD) C:\Windows\System32\atieclxx.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
(IvoSoft) C:\Program Files\Classic Shell\ClassicStartMenu.exe
(Realtek Semiconductor Corporation) C:\Program Files (x86)\Realtek\Realtek Bluetooth\BTServer.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
(Conexant Systems, Inc.) C:\Program Files\CONEXANT\cAudioFilterAgent\CAudioFilterAgent64.exe
() C:\Program Files\CONEXANT\ForteConfig\fmapp.exe
(Realtek semiconductor) C:\Windows\RTFTrack.exe
(Lenovo) C:\Program Files\Lenovo\Onekey Theater\OnekeyStudio.exe
(Lenovo) C:\Program Files\Lenovo PhoneCompanion\Phone Companion.exe
(Microsoft Corporation) C:\Windows\System32\GWX\GWX.exe
(Lenovo(beijing) Limited) C:\Program Files (x86)\Lenovo\Energy Manager\Energy Manager.exe
(Lenovo(beijing) Limited) C:\Program Files (x86)\Lenovo\Energy Manager\utility.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(McAfee, Inc.) C:\Program Files\McAfee Security Scan\3.11.163\SSScheduler.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(CyberLink Corp.) C:\Program Files (x86)\Lenovo\PowerDVD10\PDVD10Serv.exe
() C:\Program Files (x86)\DNS Unlocker\dnsseadrift.exe
(Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe
(Adobe Systems Incorporated) C:\Windows\System32\Macromed\Flash\FlashUtil_ActiveX.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\MpCmdRun.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
==================== Registry (Whitelisted) ===========================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [cAudioFilterAgent] => C:\Program Files\Conexant\cAudioFilterAgent\cAudioFilterAgent64.exe [907480 2013-09-05] (Conexant Systems, Inc.)
HKLM\...\Run: [ForteConfig] => C:\Program Files\Conexant\ForteConfig\fmapp.exe [49056 2010-10-26] ()
HKLM\...\Run: [SmartAudio] => C:\Program Files\CONEXANT\SAII\SACpl.exe [1647616 2012-06-13] (Conexant Systems, Inc.)
HKLM\...\Run: [SynTPEnh] => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2808560 2014-06-25] (Synaptics Incorporated)
HKLM\...\Run: [BtServer] => C:\Program Files (x86)\REALTEK\Realtek Bluetooth\BTServer.exe [216064 2014-01-06] (Realtek Semiconductor Corporation)
HKLM\...\Run: [RtsFT] => C:\windows\RTFTrack.exe [6340312 2014-01-21] (Realtek semiconductor)
HKLM\...\Run: [OnekeyStudio] => C:\Program Files\Lenovo\Onekey Theater\OnekeyStudio.exe [4196432 2012-09-15] (Lenovo)
HKLM\...\Run: [PhoneCompanion] => C:\Program Files\Lenovo PhoneCompanion\Phone Companion.exe [836592 2014-09-16] (Lenovo)
HKLM\...\Run: [Energy Manager] => C:\Program Files (x86)\Lenovo\Energy Manager\Energy Manager.exe [16094704 2014-09-16] (Lenovo(beijing) Limited)
HKLM\...\Run: [Lenovo Utility] => C:\Program Files (x86)\Lenovo\Energy Manager\Utility.exe [10842096 2014-09-16] (Lenovo(beijing) Limited)
HKLM\...\Run: [Classic Start Menu] => C:\Program Files\Classic Shell\ClassicStartMenu.exe [161984 2014-04-20] (IvoSoft)
HKLM-x32\...\Run: [StartCCC] => C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\amd64\CLIStart.exe [767200 2014-06-25] (Advanced Micro Devices, Inc.)
HKLM-x32\...\Run: [UpdateP2GShortCut] => C:\Program Files (x86)\Lenovo\Power2Go\MUITransfer\MUIStartMenu.exe [214312 2011-12-07] (CyberLink Corp.)
HKLM-x32\...\Run: [mncwvwsfSrv] => C:\windows\SysWOW64\mncwvwsf.vbe [7670 2014-03-05] ()
HKLM-x32\...\Run: [NtVdmSrv] => C:\windows\inf\ntvdm.vbe
HKLM-x32\...\Run: [MSStp] => C:\windows\inf\msstp.vbe [1584 2014-03-05] ()
HKLM-x32\...\Run: [mncjxdjSrv] => C:\windows\SysWOW64\mncjxdj.vbe [7670 2014-03-05] ()
HKU\S-1-5-21-4198438056-3133198569-554230774-1002\...\Run: [GoogleChromeAutoLaunch_721577D41E77D440C916E2687EBA0267] => C:\Program Files (x86)\Google\Chrome\Application\chrome.exe [813896 2015-07-07] (Google Inc.)
HKU\S-1-5-21-4198438056-3133198569-554230774-1002\...\MountPoints2: {f7bfb0cc-fe25-11e4-827c-38b1db5ead96} - "F:\Startme.exe"
ShellIconOverlayIdentifiers: [00001LenovoSyncComplete] -> {1E9CED2C-E7B4-4C47-B07A-25416393B67B} => C:\Program Files\Hightail\Hightail for Lenovo\YSINSE64.dll [2014-06-23] (Hightail Inc.)
ShellIconOverlayIdentifiers: [00002LenovoSyncActive] -> {C1285F4D-918F-4EF2-BC94-CAD5B118C835} => C:\Program Files\Hightail\Hightail for Lenovo\YSINSE64.dll [2014-06-23] (Hightail Inc.)
ShellIconOverlayIdentifiers: [00003LenovoSyncError] -> {CE5633DA-1488-4D1D-9A9B-B500297D4A8C} => C:\Program Files\Hightail\Hightail for Lenovo\YSINSE64.dll [2014-06-23] (Hightail Inc.)
ShellIconOverlayIdentifiers: [00004LenovoLocalOnly] -> {C7362DA9-D3AC-4C17-B2F5-2F1823FA04C3} => C:\Program Files\Hightail\Hightail for Lenovo\YSINSE64.dll [2014-06-23] (Hightail Inc.)
ShellIconOverlayIdentifiers-x32: [00001LenovoSyncComplete] -> {1E9CED2C-E7B4-4C47-B07A-25416393B67B} => C:\Program Files (x86)\Hightail\Hightail for Lenovo\YSINSE.dll [2014-06-23] (Hightail Inc.)
ShellIconOverlayIdentifiers-x32: [00002LenovoSyncActive] -> {C1285F4D-918F-4EF2-BC94-CAD5B118C835} => C:\Program Files (x86)\Hightail\Hightail for Lenovo\YSINSE.dll [2014-06-23] (Hightail Inc.)
ShellIconOverlayIdentifiers-x32: [00003LenovoSyncError] -> {CE5633DA-1488-4D1D-9A9B-B500297D4A8C} => C:\Program Files (x86)\Hightail\Hightail for Lenovo\YSINSE.dll [2014-06-23] (Hightail Inc.)
ShellIconOverlayIdentifiers-x32: [00004LenovoLocalOnly] -> {C7362DA9-D3AC-4C17-B2F5-2F1823FA04C3} => C:\Program Files (x86)\Hightail\Hightail for Lenovo\YSINSE.dll [2014-06-23] (Hightail Inc.)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\McAfee Security Scan Plus.lnk [2014-12-25]
ShortcutTarget: McAfee Security Scan Plus.lnk -> C:\Program Files\McAfee Security Scan\3.11.163\SSScheduler.exe (McAfee, Inc.)
CHR HKLM\SOFTWARE\Policies\Google: Restriction <======= ATTENTION
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
Hosts: 0.0.0.1 mssplus.mcafee.com
Tcpip\Parameters: [DhcpNameServer] 10.0.0.138
Tcpip\..\Interfaces\{0826528E-6122-4F77-92A1-CCF0A846CB33}: [NameServer] 82.163.143.172,82.163.142.174
Tcpip\..\Interfaces\{0826528E-6122-4F77-92A1-CCF0A846CB33}: [DhcpNameServer] 10.0.0.138
Tcpip\..\Interfaces\{A67282DE-1FD5-4F0A-9F44-5488AA98A3E8}: [DhcpNameServer] 192.168.2.1
Internet Explorer:
==================
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.msn.com/?pc=MSE1
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.msn.com/?pc=MSE1
HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.mystartsearch.com/web/?type=ds&ts=1 ... earchTerms}
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.mystartsearch.com/web/?type=ds&ts=1 ... earchTerms}
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.mystartsearch.com/?type=hp&ts=14242 ... X84GXT3EAT
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.mystartsearch.com/?type=hp&ts=14242 ... X84GXT3EAT
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://www.mystartsearch.com/web/?type=ds&ts=1 ... earchTerms}
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://www.mystartsearch.com/web/?type=ds&ts=1 ... earchTerms}
HKU\S-1-5-21-4198438056-3133198569-554230774-1002\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.msn.com/?pc=MSE1
HKU\S-1-5-21-4198438056-3133198569-554230774-1002\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.mystartsearch.com/?type=hp&ts=14242 ... X84GXT3EAT
HKU\S-1-5-21-4198438056-3133198569-554230774-1002\Software\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = hxxp://www.lenovo.com
SearchScopes: HKLM -> DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = hxxp://www.bing.com/search?q={searchTerms}&form=MSSEDF&pc=MSE1
SearchScopes: HKLM -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKLM -> {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = hxxp://www.bing.com/search?q={searchTerms}&form=MSSEDF&pc=MSE1
SearchScopes: HKLM-x32 -> DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = hxxp://www.bing.com/search?q={searchTerms}&form=MSSEDF&pc=MSE1
SearchScopes: HKLM-x32 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKLM-x32 -> {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = hxxp://www.bing.com/search?q={searchTerms}&form=MSSEDF&pc=MSE1
SearchScopes: HKU\S-1-5-21-4198438056-3133198569-554230774-1002 -> {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = hxxp://www.mystartsearch.com/web/?type=ds&ts=1 ... earchTerms}
FireFox:
========
FF ProfilePath: C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\fyl0t5bl.default-1437126649091
FF Plugin: @adobe.com/FlashPlayer -> C:\windows\system32\Macromed\Flash\NPSWF64_19_0_0_185.dll [2015-09-22] ()
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\windows\SysWOW64\Macromed\Flash\NPSWF32_19_0_0_185.dll [2015-09-22] ()
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.27.5\npGoogleUpdate3.dll [2015-06-16] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.27.5\npGoogleUpdate3.dll [2015-06-16] (Google Inc.)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll [2015-06-29] (Adobe Systems Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\np-mswmp.dll [2007-04-10] (Microsoft Corporation)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\nppdf32.dll [2015-06-29] (Adobe Systems Inc.)
FF Extension: SSAveerExtensioon - C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\fyl0t5bl.default-1437126649091\Extensions\AnE@S.com [2015-08-07]
FF Extension: The AdBlocker - C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\fyl0t5bl.default-1437126649091\Extensions\chdrdfoofd_fvdef@qrdkdqnymijvofby.com [2015-08-31]
FF Extension: RoboSaiver - C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\fyl0t5bl.default-1437126649091\Extensions\f5zJ@N.net [2015-08-26]
FF Extension: BBitSaVer - C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\fyl0t5bl.default-1437126649091\Extensions\oLG@4U1E.net [2015-08-03]
FF HKLM-x32\...\Firefox\Extensions: [searchengine@gmail.com] - C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\b9l3tw00.default\extensions\searchengine@gmail.com => not found
Chrome:
=======
CHR dev: Chrome dev build detected! <======= ATTENTION
CHR StartupUrls: Default -> "hxxp://search.gboxapp.com/"
CHR Profile: C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (Prezentace Google) - C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2015-06-16]
CHR Extension: (Wise Ads Block) - C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\alcmakjhknigccfidaelkafjmfifkhkc [2015-08-26]
CHR Extension: (Dokumenty Google) - C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2015-06-16]
CHR Extension: (Disk Google) - C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2015-06-16]
CHR Extension: (YouTube) - C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2015-06-16]
CHR Extension: (Vyhledávání Google) - C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2015-06-16]
CHR Extension: (Tabulky Google) - C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2015-06-16]
CHR Extension: (Platby Internetového obchodu Chrome) - C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2015-06-16]
CHR Extension: (Gmail) - C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2015-06-16]
==================== Services (Whitelisted) ========================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R2 AMD FUEL Service; C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe [344064 2014-06-25] (Advanced Micro Devices, Inc.) [File not signed]
R2 BTDevManager; C:\Program Files (x86)\REALTEK\Realtek Bluetooth\BTDevMgr.exe [84992 2014-01-22] () [File not signed]
S3 Lenovo EasyPlus Hotspot; C:\Program Files (x86)\Common Files\lenovo\easyplussdk\bin\EPHotspot64.exe [533760 2014-06-03] (Lenovo)
R2 Lenovo System Agent Service; C:\Program Files\Lenovo\iMController\SystemAgentService.exe [584960 2014-05-22] (LENOVO INCORPORATED.)
R2 LenovoWiFiHotspotSvr; C:\Windows\System32\LenovoWiFiHotspotSvr.exe [198192 2014-09-16] (Lenovo(beijing) Limited)
R2 LUService; C:\Program Files (x86)\Lenovo\Lenovo Updates\LUService.exe [38896 2014-02-18] (Lenovo(beijing) Limited)
S3 McComponentHostService; C:\Program Files\McAfee Security Scan\3.11.163\McCHSvc.exe [289256 2015-07-31] (McAfee, Inc.)
R2 PhoneCompanionPusher; C:\Program Files\Lenovo PhoneCompanion\PhoneCompanionPusher.exe [288240 2014-09-16] (Lenovo)
S3 PhoneCompanionVap; C:\Program Files\Lenovo PhoneCompanion\PhoneCompanionVap.exe [308720 2014-09-16] (Lenovo)
R2 RichVideo64; C:\Program Files\CyberLink\Shared files\RichVideo64.exe [390632 2012-04-25] ()
R2 SynTPEnhService; C:\Program Files\Synaptics\SynTP\SynTPEnhService.exe [190704 2014-06-25] (Synaptics Incorporated)
R2 VeriFaceSrv; C:\Program Files (x86)\Lenovo\Lenovo VeriFace Pro\VfConnectorService.exe [68880 2014-09-16] ()
R3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [366520 2015-02-04] (Microsoft Corporation)
R2 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [23792 2015-02-04] (Microsoft Corporation)
S2 gupdate; "C:\Program Files (x86)\Google\Update\GoogleUpdate.exe" /svc [X]
S3 gupdatem; "C:\Program Files (x86)\Google\Update\GoogleUpdate.exe" /medsvc [X]
S2 ReimageRealTimeProtector; C:\Program Files\Reimage\Reimage Protector\ReiGuard.exe [X]
S3 TrustedInstaller; %SystemRoot%\servicing\TrustedInstaller.exe [X]
===================== Drivers (Whitelisted) ==========================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R0 amdkmpfd; C:\Windows\System32\drivers\amdkmpfd.sys [36608 2013-12-14] (Advanced Micro Devices, Inc.)
R2 AODDriver4.3; C:\Program Files\ATI Technologies\ATI.ACE\Fuel\amd64\AODDriver2.sys [59616 2014-02-12] (Advanced Micro Devices)
R2 APXACC; C:\Windows\system32\DRIVERS\appexDrv.sys [225504 2014-03-28] (AppEx Networks Corporation)
R3 AtiHDAudioService; C:\Windows\system32\drivers\AtihdWB6.sys [222720 2014-03-12] (Advanced Micro Devices)
R3 BthLEEnum; C:\Windows\system32\DRIVERS\BthLEEnum.sys [226304 2014-03-18] (Microsoft Corporation)
S0 ebdrv; C:\Windows\System32\drivers\evbda.sys [3357024 2013-08-22] (Broadcom Corporation)
S3 NETwNe64; C:\Windows\system32\DRIVERS\NETwew02.sys [4649440 2013-06-18] (Intel Corporation)
R3 RtkBtFilter; C:\Windows\system32\DRIVERS\RtkBtfilter.sys [558296 2014-04-12] (Realtek Semiconductor Corporation)
R3 rtsuvc; C:\Windows\system32\DRIVERS\rtsuvc.sys [9105624 2014-01-21] (Realtek Semiconductor Corp.)
R3 RTWlanE; C:\Windows\system32\DRIVERS\rtwlane.sys [3410136 2014-04-11] (Realtek Semiconductor Corporation )
S0 WdBoot; C:\Windows\System32\drivers\WdBoot.sys [44024 2015-02-04] (Microsoft Corporation)
R0 WdFilter; C:\Windows\System32\drivers\WdFilter.sys [264000 2015-02-04] (Microsoft Corporation)
R3 WdNisDrv; C:\Windows\System32\Drivers\WdNisDrv.sys [114496 2015-02-04] (Microsoft Corporation)
S3 wsvd; C:\Windows\system32\DRIVERS\wsvd.sys [102376 2012-06-14] ("CyberLink)
S1 atshpnjq; \??\C:\windows\system32\drivers\atshpnjq.sys [X]
S1 awfztrnp; \??\C:\windows\system32\drivers\awfztrnp.sys [X]
S1 bgtgmhvu; \??\C:\windows\system32\drivers\bgtgmhvu.sys [X]
S1 ivtahkky; \??\C:\windows\system32\drivers\ivtahkky.sys [X]
==================== NetSvcs (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
==================== One Month Created files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2015-10-02 19:22 - 2015-10-02 19:22 - 00019038 _____ C:\Users\Owner\Desktop\FRST.txt
2015-10-02 19:20 - 2015-10-02 19:22 - 00000000 ____D C:\FRST
2015-10-02 19:20 - 2015-10-02 19:20 - 02192384 _____ (Farbar) C:\Users\Owner\Desktop\FRST64.exe
2015-10-02 19:19 - 2015-10-02 19:19 - 00112640 _____ (forum.viry.cz) C:\Users\Owner\Desktop\FRSTLauncher.exe
2015-10-02 19:19 - 2015-10-02 19:19 - 00015327 _____ C:\Users\Owner\Desktop\LM.bat
2015-10-02 19:16 - 2015-10-02 19:19 - 00029696 _____ C:\Users\Owner\AppData\Local\MSGBOX.EXE
2015-09-27 17:09 - 2015-05-10 18:38 - 06669238 _____ C:\Users\Owner\Downloads\Kabát---Brousíme-nože---PROMO-SINGL---2015-(256kbit).m4a
2015-09-27 16:47 - 2015-09-27 17:06 - 326094085 _____ C:\Users\Owner\Downloads\100-Wiz-Khalifa-&-Iggy-Azalea---Go-Hard-Or-Go-Home.rar
2015-09-26 15:05 - 2015-09-26 15:05 - 00026356 _____ C:\windows\System32\Tasks\DNSSEADRIFT
2015-09-26 15:05 - 2015-09-26 15:05 - 00000000 ____D C:\Program Files (x86)\DNS Unlocker
2015-09-21 13:41 - 2015-09-21 13:49 - 00000000 ____D C:\Users\Owner\Downloads\hiphop
2015-09-19 17:22 - 2015-10-01 18:07 - 00001279 _____ C:\Users\Owner\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Wi-FiHotspotChgToast.lnk
2015-09-19 17:18 - 2015-09-19 17:27 - 00000000 ____D C:\Users\Owner\Desktop\EDM
2015-09-03 20:09 - 2015-09-03 20:09 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\McAfee Security Scan Plus
2015-09-03 20:09 - 2015-09-03 20:09 - 00000000 ____D C:\Program Files\McAfee Security Scan
==================== One Month Modified files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2015-10-02 19:22 - 2014-12-09 06:03 - 00003596 _____ C:\windows\System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-4198438056-3133198569-554230774-1002
2015-10-02 19:17 - 2014-12-09 06:30 - 00000000 ____D C:\Users\Owner\AppData\Roaming\ClassicShell
2015-10-02 19:17 - 2014-12-09 05:57 - 01267941 _____ C:\Users\Owner\AppData\Local\BTServer.log
2015-10-02 19:01 - 2014-09-16 02:55 - 01694514 _____ C:\windows\WindowsUpdate.log
2015-10-02 19:00 - 2013-08-22 17:36 - 00000000 ____D C:\windows\system32\sru
2015-10-02 18:49 - 2014-12-09 06:22 - 00000914 _____ C:\windows\Tasks\Adobe Flash Player Updater.job
2015-10-02 18:43 - 2015-01-25 22:32 - 00000479 _____ C:\Users\Owner\rgut
2015-10-02 18:42 - 2014-09-16 03:35 - 00739924 _____ C:\windows\system32\perfh005.dat
2015-10-02 18:42 - 2014-09-16 03:35 - 00151610 _____ C:\windows\system32\perfc005.dat
2015-10-02 18:42 - 2014-03-18 11:53 - 01745984 _____ C:\windows\system32\PerfStringBackup.INI
2015-10-02 17:16 - 2014-09-16 03:32 - 08680212 _____ C:\Users\Public\CAFADEBUG.log
2015-10-02 15:05 - 2015-08-15 03:05 - 00000360 _____ C:\windows\Tasks\Bidaily Synchronize Task[8da6].job
2015-10-02 13:57 - 2014-12-09 06:09 - 00003974 _____ C:\windows\System32\Tasks\User_Feed_Synchronization-{118BDF86-4DAF-493B-BB27-91CAA24A69C7}
2015-10-01 18:07 - 2014-09-16 04:38 - 00000000 ____D C:\ProgramData\LU
2015-10-01 17:35 - 2013-08-22 16:46 - 00050003 _____ C:\windows\setupact.log
2015-10-01 17:35 - 2013-08-22 16:45 - 00000006 ____H C:\windows\Tasks\SA.DAT
2015-10-01 17:34 - 2014-09-16 04:15 - 00006656 _____ C:\windows\system32\VfService.trf
2015-10-01 17:34 - 2014-09-16 03:27 - 00065536 _____ C:\windows\system32\spu_storage.bin
2015-10-01 17:34 - 2013-08-22 15:25 - 00262144 ___SH C:\windows\system32\config\BBI
2015-09-29 11:51 - 2015-08-06 21:58 - 00000000 ____D C:\Program Files (x86)\SaVerExxtensionn
2015-09-26 10:09 - 2013-08-22 17:36 - 00000000 ____D C:\windows\AppReadiness
2015-09-22 19:49 - 2014-12-09 06:22 - 00003802 _____ C:\windows\System32\Tasks\Adobe Flash Player Updater
2015-09-20 11:20 - 2015-08-26 10:52 - 00000000 ____D C:\Program Files (x86)\RoBoSAver
2015-09-20 07:12 - 2015-08-26 10:55 - 00000000 ____D C:\Program Files (x86)\Wise Ads Block
2015-09-20 07:11 - 2015-08-12 08:44 - 00000000 ____D C:\Program Files (x86)\BestaSaveFourYou
2015-09-20 07:11 - 2015-08-03 15:49 - 00000000 ____D C:\Program Files (x86)\BitSoaver
2015-09-20 07:11 - 2015-08-03 15:48 - 00000000 ____D C:\Program Files (x86)\BBitSaVer
2015-09-20 07:11 - 2015-08-03 07:21 - 00000000 ____D C:\Program Files (x86)\AntiPorn Pro The best AntiPorn addon
2015-09-20 07:10 - 2015-08-06 22:00 - 00000000 ____D C:\Program Files (x86)\My IP address
2015-09-20 07:10 - 2015-08-03 15:48 - 00000000 ____D C:\Program Files (x86)\QR Code Maker and Decoder
2015-09-20 07:10 - 2015-08-03 07:22 - 00000000 ____D C:\Program Files (x86)\RanndomPricE
2015-09-20 07:10 - 2015-08-03 07:22 - 00000000 ____D C:\Program Files (x86)\RaandomPrIce
2015-09-20 07:10 - 2015-08-03 07:21 - 00000000 ____D C:\Program Files (x86)\RanedOOmPRiCE
2015-09-20 07:09 - 2015-06-05 09:38 - 00000000 ____D C:\Program Files (x86)\SAveLOts
2015-09-20 07:09 - 2015-06-05 09:38 - 00000000 ____D C:\Program Files (x86)\SaveeLotss
2015-09-20 07:09 - 2015-06-05 09:37 - 00000000 ____D C:\Program Files (x86)\SaveaLottss
2015-09-20 07:09 - 2015-04-26 14:01 - 00000000 ____D C:\Program Files (x86)\sound on click
2015-09-20 07:08 - 2015-08-06 22:00 - 00000000 ____D C:\Program Files (x86)\SSAveerExtensioon
2015-09-20 07:08 - 2015-02-18 14:26 - 00000000 ____D C:\Program Files (x86)\UUniDealeS e
2015-09-20 07:02 - 2015-05-17 13:06 - 00000000 ____D C:\Program Files (x86)\Epic Soccer Barcelona
2015-09-20 07:01 - 2015-06-05 18:24 - 00000000 ____D C:\Program Files (x86)\SickBeardConnect
2015-09-20 07:01 - 2015-05-17 13:06 - 00000000 ____D C:\Program Files (x86)\ShoPDrop
2015-09-20 07:01 - 2015-05-17 13:06 - 00000000 ____D C:\Program Files (x86)\RegularoDealS
2015-09-20 07:01 - 2015-02-18 14:27 - 00000000 ____D C:\Program Files (x86)\UniDeals
2015-09-20 06:57 - 2015-08-26 10:51 - 00000000 ____D C:\Program Files (x86)\RoboSaiver
2015-09-20 06:57 - 2015-04-26 14:02 - 00000000 ____D C:\Program Files (x86)\CheeapMe
2015-09-20 06:57 - 2015-02-18 14:27 - 00000000 ____D C:\Program Files (x86)\Hearthstone Stream Browser
2015-09-20 06:55 - 2015-06-11 21:36 - 00000000 ____D C:\Program Files (x86)\MicrOOMaSteers
2015-09-19 17:12 - 2014-12-09 05:56 - 00000000 ____D C:\Users\Owner
2015-09-19 17:11 - 2015-04-04 23:50 - 00000000 ___SD C:\windows\system32\GWX
2015-09-19 17:10 - 2014-12-25 18:48 - 00000000 ____D C:\ProgramData\McAfee Security Scan
2015-09-19 17:10 - 2014-12-09 06:21 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2015-09-19 17:10 - 2014-12-09 05:58 - 00000000 ____D C:\Users\Owner\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Lenovo
2015-09-19 17:04 - 2013-08-22 17:36 - 00000000 ____D C:\windows\registration
2015-09-19 17:03 - 2015-06-16 10:28 - 00000000 ____D C:\Users\Owner\AppData\Local\Google
2015-09-15 08:31 - 2014-03-18 11:44 - 00019736 _____ C:\windows\PFRO.log
2015-09-09 15:28 - 2015-08-03 15:48 - 00000000 ____D C:\Program Files (x86)\BitSaveur
2015-09-09 15:28 - 2015-06-12 07:26 - 00000000 ____D C:\Program Files (x86)\TakeTHeCoupon
2015-09-09 15:28 - 2015-04-29 14:55 - 00000000 ____D C:\Program Files (x86)\BeesTSaveForYYoue
2015-09-09 15:26 - 2015-05-17 13:05 - 00000000 ____D C:\Program Files (x86)\FunDEalSS
2015-09-03 20:09 - 2014-12-25 18:48 - 00001961 _____ C:\Users\Public\Desktop\McAfee Security Scan Plus.lnk
==================== Files in the root of some directories =======
2015-04-17 13:11 - 2015-08-06 21:59 - 0000079 _____ () C:\Program Files (x86)\prefs.js
2015-07-08 19:32 - 2015-08-17 22:32 - 0000020 _____ () C:\Users\Owner\AppData\Roaming\appdataFr2.bin
2015-07-15 15:37 - 2015-08-14 18:38 - 0000024 _____ () C:\Users\Owner\AppData\Roaming\appdataFr25.bin
2014-12-09 06:19 - 2015-08-23 16:01 - 0000421 _____ () C:\Users\Owner\AppData\Roaming\burnaware.ini
2014-12-09 05:57 - 2015-10-02 19:17 - 1267941 _____ () C:\Users\Owner\AppData\Local\BTServer.log
2015-08-20 09:50 - 2015-08-20 09:50 - 0000031 _____ () C:\Users\Owner\AppData\Local\burnaware.ini
2015-10-02 19:16 - 2015-10-02 19:19 - 0029696 _____ () C:\Users\Owner\AppData\Local\MSGBOX.EXE
2015-03-12 08:17 - 2015-03-12 08:17 - 0000017 _____ () C:\Users\Owner\AppData\Local\resmon.resmoncfg
2014-09-16 03:32 - 2014-09-16 03:32 - 0000000 ____H () C:\ProgramData\DP45977C.lfl
Some files in TEMP:
====================
C:\Users\Owner\AppData\Local\Temp\supoptsetup.exe
C:\Users\Owner\AppData\Local\Temp\_unps.exe
==================== Bamital & volsnap =================
(There is no automatic fix for files that do not pass verification.)
C:\windows\system32\winlogon.exe => File is digitally signed
C:\windows\system32\wininit.exe => File is digitally signed
C:\windows\explorer.exe => File is digitally signed
C:\windows\SysWOW64\explorer.exe => File is digitally signed
C:\windows\system32\svchost.exe => File is digitally signed
C:\windows\SysWOW64\svchost.exe => File is digitally signed
C:\windows\system32\services.exe => File is digitally signed
C:\windows\system32\User32.dll => File is digitally signed
C:\windows\SysWOW64\User32.dll => File is digitally signed
C:\windows\system32\userinit.exe => File is digitally signed
C:\windows\SysWOW64\userinit.exe => File is digitally signed
C:\windows\system32\rpcss.dll => File is digitally signed
C:\windows\system32\dnsapi.dll => File is digitally signed
C:\windows\SysWOW64\dnsapi.dll => File is digitally signed
C:\windows\system32\Drivers\volsnap.sys => File is digitally signed
LastRegBack: 2015-09-29 11:34
==================== End of FRST.txt ============================