Čínský malware
Napsal: 02 pro 2015 22:17
Dobrý den,
chtěl bych porposit o kontrolu logu. Při instalaci doplňku do mozily firefox se mi podařilo chytnout nějakou čínskou infekci.
Velice děkuji
Log:
Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version:01-12-2015
Ran by Daniel (administrator) on DANIEL-LENOVO (02-12-2015 22:12:24)
Running from C:\Users\Daniel\Desktop
Loaded Profiles: Daniel (Available Profiles: Daniel)
Platform: Windows 10 Education (X64) Language: Čeština (Česká republika)
Internet Explorer Version 11 (Default browser: FF)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/33 ... scan-tool/
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(Conexant Systems Inc.) C:\Windows\System32\CxAudMsg64.exe
(ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDService.exe
(National Instruments Corporation) C:\Windows\SysWOW64\lkads.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe
(National Instruments Corporation) C:\Program Files (x86)\National Instruments\MAX\nimxs.exe
(National Instruments Corporation) C:\Program Files (x86)\National Instruments\Shared\niauth\niauth_daemon.exe
(National Instruments Corporation) C:\Program Files (x86)\National Instruments\Shared\nisvcloc\nisvcloc.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamService.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe
(National Instruments Corporation) C:\Windows\SysWOW64\lktsrv.exe
(National Instruments, Inc.) C:\Windows\SysWOW64\lkcitdl.exe
(National Instruments Corporation) C:\Program Files (x86)\National Instruments\Shared\Security\nidmsrv.exe
(National Instruments Corporation) C:\Program Files (x86)\National Instruments\Shared\mDNS Responder\nimdnsResponder.exe
(National Instruments Corporation) C:\Program Files (x86)\National Instruments\Shared\NI Network Discovery\niDiscSvc.exe
(National Instruments Corporation) C:\Program Files (x86)\National Instruments\Shared\NI WebServer\SystemWebServer.exe
(National Instruments Corporation) C:\Program Files (x86)\National Instruments\Shared\Tagger\tagsrv.exe
(National Instruments Corporation) C:\Program Files (x86)\National Instruments\Shared\NI WebServer\ApplicationWebServer.exe
(National Instruments Corporation) C:\Program Files (x86)\National Instruments\Shared\NI WebServer\NIWebServiceContainer.exe
(National Instruments Corporation) C:\Program Files (x86)\National Instruments\Shared\NI WebServer\NIWebServiceContainer.exe
(National Instruments Corporation) C:\Program Files (x86)\National Instruments\Shared\NI WebServer\NIWebServiceContainer.exe
(National Instruments Corporation) C:\Program Files (x86)\National Instruments\Shared\NI WebServer\NIWebServiceContainer.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamNetworkService.exe
(National Instruments Corporation) C:\Program Files (x86)\National Instruments\Shared\NI WebServer\NIWebServiceContainer.exe
(ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDCtrl.exe
(Google Inc.) C:\Program Files (x86)\Google\Update\1.3.28.15\GoogleCrashHandler.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamUserAgent.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe
(ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDCtrlHelper.exe
(ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDIntelligent.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
(Google Inc.) C:\Program Files (x86)\Google\Update\1.3.28.15\GoogleCrashHandler64.exe
(Intel Corporation) C:\Windows\System32\igfxtray.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(Intel Corporation) C:\Windows\System32\igfxpers.exe
(Pixart Imaging Inc) C:\Windows\System32\TiltWheelMouse.exe
(Google) C:\Program Files (x86)\Google\Drive\googledrivesync.exe
(Vimicro) C:\Program Files (x86)\USB Camera\VM331STI.EXE
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(Google) C:\Program Files (x86)\Google\Drive\googledrivesync.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
() C:\Program Files\WindowsApps\Microsoft.Windows.Photos_15.1120.13270.0_x64__8wekyb3d8bbwe\Microsoft.Photos.exe
() C:\Program Files\WindowsApps\Microsoft.WindowsCalculator_10.1511.24020.0_x64__8wekyb3d8bbwe\Calculator.exe
( ) C:\Program Files (x86)\baidu\pps.exe
(Valve Corporation) C:\Program Files (x86)\Steam\Steam.exe
(Valve Corporation) C:\Program Files (x86)\Steam\bin\steamwebhelper.exe
(Valve Corporation) C:\Program Files (x86)\Common Files\Steam\SteamService.exe
(iQIYI.COM) C:\IQIYI Video\LStyle\QyKernel.exe
() C:\IQIYI Video\LStyle\Mobile\AndroidService.exe
(Tencent) C:\Program Files (x86)\Tencent\QQPCMgr\10.7.16065.215\TAOFrame.exe
(Tencent) C:\Program Files (x86)\Tencent\QQPCMgr\10.7.16065.215\QQPCRTP.exe
(Tencent) C:\Program Files (x86)\Tencent\QQPCMgr\10.7.16065.215\QQPCTray.exe
(Tencent) C:\Program Files (x86)\Common Files\Tencent\QQDownload\130\Tencentdl.exe
(Tencent) C:\Program Files (x86)\Tencent\QQPCMgr\10.7.16065.215\plugins\QMNetMon\QQPCNetFlow.exe
(Tencent) C:\Program Files (x86)\Tencent\QQPCMgr\10.7.16065.215\QQPCRealTimeSpeedup.exe
(Tencent) C:\Program Files (x86)\Common Files\Tencent\QQDownload\130\Tencentdl.exe
(Tencent) C:\Program Files (x86)\Tencent\QQPCMgr\10.7.16065.215\QQPCTray.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
==================== Registry (Whitelisted) ===========================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [ETDCtrl] => C:\Program Files\Elantech\ETDCtrl.exe [3743648 2015-09-05] (ELAN Microelectronics Corp.)
HKLM\...\Run: [MouseDriver] => C:\WINDOWS\system32\TiltWheelMouse.exe [241152 2015-10-11] (Pixart Imaging Inc)
HKLM\...\Run: [cAudioFilterAgent] => C:\Program Files\Conexant\cAudioFilterAgent\cAudioFilterAgent64.exe [935104 2014-11-25] (Conexant Systems, Inc.)
HKLM\...\Run: [SmartAudio] => C:\Program Files\CONEXANT\SAII\SACpl.exe [1830616 2014-04-10] (Conexant Systems, Inc.)
HKLM\...\Run: [NvBackend] => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe [2757424 2015-11-16] (NVIDIA Corporation)
HKLM\...\Run: [ShadowPlay] => "C:\WINDOWS\system32\rundll32.exe" C:\WINDOWS\system32\nvspcap64.dll,ShadowPlayOnSystemStart
HKLM-x32\...\Run: [331BigDog] => C:\Program Files (x86)\USB Camera\VM331STI.EXE [561672 2015-06-12] (Vimicro)
HKLM-x32\...\Run: [seznam-listicka-distribuce] => C:\Program Files (x86)\Seznam.cz\distribution\szninstall.exe [1062472 2013-05-16] ()
HKLM-x32\...\Run: [SafeQClient] => C:\Program Files (x86)\SafeQ\SafeQ_cli.exe [493056 2015-11-02] (VŠB-TU Ostrava)
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [596528 2015-11-09] (Oracle Corporation)
HKLM-x32\...\Run: [ QQPCTray] => C:\Program Files (x86)\Tencent\QQPCMgr\10.7.16065.215\QQPCTray.exe [355296 2015-12-02] (Tencent)
Winlogon\Notify\igfxcui: C:\WINDOWS\system32\igfxdev.dll (Intel Corporation)
HKU\S-1-5-21-2161712444-3510936251-563553130-1001\...\Run: [Steam] => C:\Program Files (x86)\Steam\steam.exe [3011152 2015-11-10] (Valve Corporation)
HKU\S-1-5-21-2161712444-3510936251-563553130-1001\...\Run: [cz.seznam.software.autoupdate] => C:\Users\Daniel\AppData\Roaming\Seznam.cz\szninstall.exe [1062472 2013-05-16] ()
HKU\S-1-5-21-2161712444-3510936251-563553130-1001\...\Run: [cz.seznam.software.szndesktop] => C:\Users\Daniel\AppData\Roaming\Seznam.cz\bin\wszndesktop.exe [103080 2015-05-26] ()
HKU\S-1-5-21-2161712444-3510936251-563553130-1001\...\Run: [GoogleDriveSync] => C:\Program Files (x86)\Google\Drive\googledrivesync.exe [22790776 2015-11-04] (Google)
HKU\S-1-5-21-2161712444-3510936251-563553130-1001\...\Run: [DAEMON Tools Lite Automount] => C:\Program Files\DAEMON Tools Lite\DTAgent.exe [4468056 2015-06-18] (Disc Soft Ltd)
HKU\S-1-5-21-2161712444-3510936251-563553130-1001\...\Run: [GSplay.exe] => C:\Users\Daniel\Desktop\GSplay.exe
HKU\S-1-5-21-2161712444-3510936251-563553130-1001\...\Run: [NIRegistrationWizard] => C:\Program Files (x86)\National Instruments\Shared\RegistrationWizard\Bin\RegistrationWizard.exe [847000 2013-04-19] ()
HKU\S-1-5-21-2161712444-3510936251-563553130-1001\...\Run: [apphide] => C:\Program Files (x86)\baidu\pps.exe [81920 2015-11-04] ( )
HKU\S-1-5-21-2161712444-3510936251-563553130-1001\...\Run: [HCDNClient] => C:\IQIYI Video\LStyle\QyKernel.exe [576104 2015-08-04] (iQIYI.COM)
HKU\S-1-5-21-2161712444-3510936251-563553130-1001\...\MountPoints2: {1dbc3f99-8472-11e5-9bd5-b888e373a893} - "E:\LG_PC_Programs.exe"
HKU\S-1-5-21-2161712444-3510936251-563553130-1001\...\MountPoints2: {9927f19a-7030-11e5-9bd0-b888e373a893} - "E:\autorun.exe"
AppInit_DLLs: C:\WINDOWS\system32\nvinitx.dll => C:\WINDOWS\system32\nvinitx.dll [177600 2015-11-16] (NVIDIA Corporation)
AppInit_DLLs-x32: C:\WINDOWS\SysWOW64\nvinit.dll => C:\WINDOWS\SysWOW64\nvinit.dll [155792 2015-11-16] (NVIDIA Corporation)
ShellIconOverlayIdentifiers: [ GoogleDriveBlacklisted] -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D42} => C:\Program Files (x86)\Google\Drive\googledrivesync64.dll [2015-11-04] (Google)
ShellIconOverlayIdentifiers: [ GoogleDriveSynced] -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D40} => C:\Program Files (x86)\Google\Drive\googledrivesync64.dll [2015-11-04] (Google)
ShellIconOverlayIdentifiers: [ GoogleDriveSyncing] -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D41} => C:\Program Files (x86)\Google\Drive\googledrivesync64.dll [2015-11-04] (Google)
ShellIconOverlayIdentifiers: [.QMDeskTopGCIcon] -> {B7667919-3765-4815-A66D-98A09BE662D6} => C:\Program Files (x86)\Tencent\QQPCMgr\10.7.16065.215\QMGCShellExt64.dll [2015-04-07] (Tencent)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\NI Error Reporting.lnk [2015-11-24]
ShortcutTarget: NI Error Reporting.lnk -> C:\Program Files (x86)\National Instruments\Shared\NI Error Reporting\nierserver.exe (National Instruments Corporation)
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
Winsock: Catalog5 07 C:\Program Files (x86)\National Instruments\Shared\mDNS Responder\nimdnsNSP.dll [26512 2014-06-06] (National Instruments Corporation)
Winsock: Catalog5-x64 07 C:\Program Files\National Instruments\Shared\mDNS Responder\nimdnsNSP.dll [28560 2014-06-06] (National Instruments Corporation)
Tcpip\Parameters: [DhcpNameServer] 10.0.0.1 10.0.1.1
Tcpip\..\Interfaces\{952e9e30-7837-4bd5-b7ce-835e1409f774}: [DhcpNameServer] 10.0.0.1 10.0.1.1
Internet Explorer:
==================
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.hao123.com/?tn=92280131_hao_pg
HKU\S-1-5-21-2161712444-3510936251-563553130-1001\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.hao123.com/?tn=92280131_hao_pg
HKU\S-1-5-21-2161712444-3510936251-563553130-1001\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://windows.microsoft.com/cs-cz/hotmail/home?ocid=iehp
SearchScopes: HKU\S-1-5-21-2161712444-3510936251-563553130-1001 -> {069202F1-27FC-4601-A5CA-41F878F17CB4} URL = hxxp://encyklopedie.seznam.cz/search?q={searchTerms}&sourceid=QuickSearch_16194
SearchScopes: HKU\S-1-5-21-2161712444-3510936251-563553130-1001 -> {0D95C45A-4BB5-40A8-AAC6-45A9A2CA3FDC} URL = hxxp://slovnik.seznam.cz/?q={searchTerms}&lang=cz_en&sourceid=QuickSearch_16194
SearchScopes: HKU\S-1-5-21-2161712444-3510936251-563553130-1001 -> {17871175-3CF6-4B2C-94D8-C8E87473DBBA} URL = hxxp://search.seznam.cz/?q={searchTerms}&sourceid=QuickSearch_16194
SearchScopes: HKU\S-1-5-21-2161712444-3510936251-563553130-1001 -> {1C10EE84-0FDE-4C21-92AA-A8E14B148BF1} URL = hxxp://tv.seznam.cz/hledej?w={searchTerms}&sourceid=QuickSearch_16194
SearchScopes: HKU\S-1-5-21-2161712444-3510936251-563553130-1001 -> {9BF95EE0-8409-4BE3-8C75-761AB9324909} URL = hxxp://slovnik.seznam.cz/?q={searchTerms}&lang=en_cz&sourceid=QuickSearch_16194
SearchScopes: HKU\S-1-5-21-2161712444-3510936251-563553130-1001 -> {A1FBF928-091F-4EA8-BD03-00673561F5CD} URL = hxxp://www.firmy.cz/?q={searchTerms}&sourceid= ... arch_16194
SearchScopes: HKU\S-1-5-21-2161712444-3510936251-563553130-1001 -> {BE5B2B07-E2DB-4C66-9A79-AA1CDA6D160B} URL = hxxp://www.zbozi.cz/?q={searchTerms}&r=campmoz ... arch_16194
SearchScopes: HKU\S-1-5-21-2161712444-3510936251-563553130-1001 -> {CE5AAD91-AB43-45DC-94F4-1C9C48ADDEF3} URL = hxxp://www.mapy.cz/?query={searchTerms}&source ... arch_16194
SearchScopes: HKU\S-1-5-21-2161712444-3510936251-563553130-1001 -> {E5F225C3-804F-47D5-81B9-AB6A482B2607} URL = hxxp://www.novinky.cz/hledej?w={searchTerms}&s ... arch_16194
BHO: 电脑管家网页防火墙 -> {7C260B4B-F7A0-40B5-B403-BEFCDC6A4C3B} -> C:\Program Files (x86)\Tencent\QQPCMgr\10.7.16065.215\TSWebMon64.dat [2015-12-02] (Tencent)
BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL [2013-03-06] (Microsoft Corporation)
BHO-x32: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files (x86)\Microsoft Office\Office14\GROOVEEX.DLL [2013-12-18] (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_66\bin\ssv.dll [2015-11-23] (Oracle Corporation)
BHO-x32: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL [2013-03-06] (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_66\bin\jp2ssv.dll [2015-11-23] (Oracle Corporation)
BHO-x32: °®ĆćŇŐÖúĘÖ -> {FB4F6285-4C32-49F2-950F-A5998F9CEC6C} -> C:\IQIYI Video\LStyle\Accelerator\IEHelper.dll [2015-08-04] (爱奇艺)
FireFox:
========
FF ProfilePath: C:\Users\Daniel\AppData\Roaming\Mozilla\Firefox\Profiles\xu00lnfi.default
FF Homepage: hxxps://www.seznam.cz/
FF Plugin: @adobe.com/FlashPlayer -> C:\WINDOWS\system32\Macromed\Flash\NPSWF64_19_0_0_245.dll [2015-11-10] ()
FF Plugin: @iqiyi.com/npclient -> C:\IQIYI Video\LStyle\npclient.dll [2015-08-04] ()
FF Plugin: @iqiyi.com/npWebPlayer -> C:\IQIYI Video\LStyle\npWebPlayer.dll [No File]
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files\Microsoft Silverlight\5.1.40728.0\npctrl.dll [2015-07-28] ( Microsoft Corporation)
FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~1\MICROS~1\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\WINDOWS\SysWOW64\Macromed\Flash\NPSWF32_19_0_0_245.dll [2015-11-10] ()
FF Plugin-x32: @iqiyi.com/npclient -> C:\IQIYI Video\LStyle\npclient.dll [2015-08-04] ()
FF Plugin-x32: @iqiyi.com/npWebPlayer -> C:\IQIYI Video\LStyle\npWebPlayer.dll [No File]
FF Plugin-x32: @java.com/DTPlugin,version=11.66.2 -> C:\Program Files (x86)\Java\jre1.8.0_66\bin\dtplugin\npDeployJava1.dll [2015-11-23] (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=11.66.2 -> C:\Program Files (x86)\Java\jre1.8.0_66\bin\plugin2\npjp2.dll [2015-11-23] (Oracle Corporation)
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files (x86)\Microsoft Silverlight\5.1.40728.0\npctrl.dll [2015-07-28] ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL [2010-03-24] (Microsoft Corporation)
FF Plugin-x32: @qq.com/QQPCMgr -> C:\Program Files (x86)\Tencent\QQPCMgr\10.7.16065.215\npQMExtensionsMozilla.dll [2015-12-02] (Tencent Technology (Shenzhen) Company Limited)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.28.15\npGoogleUpdate3.dll [2015-09-17] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.28.15\npGoogleUpdate3.dll [2015-09-17] (Google Inc.)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll [2015-09-30] (Adobe Systems Inc.)
FF Plugin HKU\S-1-5-21-2161712444-3510936251-563553130-1001: @iqiyi.com/npWebPlayer -> C:\IQIYI Video\LStyle\npWebPlayer.dll [No File]
FF Plugin HKU\S-1-5-21-2161712444-3510936251-563553130-1001: @unity3d.com/UnityPlayer,version=1.0 -> C:\Users\Daniel\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll [2014-12-05] (Unity Technologies ApS)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\nplv2014win32.dll [2015-04-30] (National Instruments)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\nplv2015win32.dll [2015-06-17] (National Instruments)
FF Extension: Adblock Plus - C:\Users\Daniel\AppData\Roaming\Mozilla\Firefox\Profiles\xu00lnfi.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2015-11-25]
==================== Services (Whitelisted) ========================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
S3 Disc Soft Lite Bus Service; C:\Program Files\DAEMON Tools Lite\DiscSoftBusService.exe [1268568 2015-06-18] (Disc Soft Ltd)
R2 ETDService; C:\Program Files\Elantech\ETDService.exe [135072 2015-09-05] (ELAN Microelectronics Corp.)
R2 GfExperienceService; C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe [1156400 2015-11-16] (NVIDIA Corporation)
R2 LkCitadelServer; C:\WINDOWS\SysWOW64\lkcitdl.exe [695136 2014-08-07] (National Instruments, Inc.)
R2 lkClassAds; C:\WINDOWS\SysWOW64\lkads.exe [53544 2015-06-01] (National Instruments Corporation)
R2 lkTimeSync; C:\WINDOWS\SysWOW64\lktsrv.exe [63792 2015-06-01] (National Instruments Corporation)
R2 mxssvr; C:\Program Files (x86)\National Instruments\MAX\nimxs.exe [84792 2015-06-12] (National Instruments Corporation)
R2 NIApplicationWebServer; C:\Program Files (x86)\National Instruments\Shared\NI WebServer\ApplicationWebServer.exe [57184 2015-06-03] (National Instruments Corporation)
S4 NIApplicationWebServer64; C:\Program Files\National Instruments\Shared\NI WebServer\ApplicationWebServer.exe [80736 2015-06-03] (National Instruments Corporation)
R2 niauth; C:\Program Files (x86)\National Instruments\Shared\niauth\niauth_daemon.exe [571712 2015-06-02] (National Instruments Corporation)
R2 NIDomainService; C:\Program Files (x86)\National Instruments\Shared\Security\nidmsrv.exe [399152 2015-06-01] (National Instruments Corporation)
S3 NILM License Manager; C:\Program Files (x86)\National Instruments\Shared\License Manager\Bin\lmgrd.exe [1427688 2010-08-02] (Macrovision Corporation)
R2 nimDNSResponder; C:\Program Files (x86)\National Instruments\Shared\mDNS Responder\nimdnsResponder.exe [320368 2014-06-06] (National Instruments Corporation)
R2 NINetworkDiscovery; C:\Program Files (x86)\National Instruments\Shared\NI Network Discovery\niDiscSvc.exe [177024 2015-06-12] (National Instruments Corporation)
R2 NiSvcLoc; C:\Program Files (x86)\National Instruments\Shared\niSvcLoc\nisvcloc.exe [89928 2015-06-02] (National Instruments Corporation)
R2 NISystemWebServer; C:\Program Files (x86)\National Instruments\Shared\NI WebServer\SystemWebServer.exe [57168 2015-06-03] (National Instruments Corporation)
R2 NITaggerService; C:\Program Files (x86)\National Instruments\Shared\Tagger\tagsrv.exe [703304 2015-06-11] (National Instruments Corporation)
R2 NvNetworkService; C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe [1872688 2015-11-16] (NVIDIA Corporation)
R3 NvStreamNetworkSvc; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamNetworkService.exe [8133424 2015-11-16] (NVIDIA Corporation)
R2 NvStreamSvc; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamService.exe [5915440 2015-11-16] (NVIDIA Corporation)
R2 QQPCRTP; C:\Program Files (x86)\Tencent\QQPCMgr\10.7.16065.215\QQPCRTP.exe [297608 2015-12-02] (Tencent)
R3 TAOFrame; C:\Program Files (x86)\Tencent\QQPCMgr\10.7.16065.215\TAOFrame.exe [293728 2015-12-02] (Tencent)
S3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [362928 2015-07-10] (Microsoft Corporation)
S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [24864 2015-07-10] (Microsoft Corporation)
===================== Drivers (Whitelisted) ==========================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R3 BCM43XX; C:\Windows\system32\DRIVERS\bcmwl63a.sys [7593176 2015-07-10] (Broadcom Corporation)
R3 dtlitescsibus; C:\Windows\System32\drivers\dtlitescsibus.sys [30264 2015-10-13] (Disc Soft Ltd)
R3 NvStreamKms; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys [19760 2015-11-16] (NVIDIA Corporation)
R3 nvvad_WaveExtensible; C:\Windows\system32\drivers\nvvad64v.sys [50472 2015-11-16] (NVIDIA Corporation)
R1 QMUdisk; C:\Program Files (x86)\Tencent\QQPCMgr\10.7.16065.215\QMUdisk64.sys [80184 2015-12-02] (Tencent)
R2 QQSysMonX64; C:\Program Files (x86)\Tencent\QQPCMgr\10.7.16065.215\QQSysMonX64.sys [127800 2015-12-02] (电脑管家)
S3 RTSUER; C:\Windows\system32\Drivers\RtsUer.sys [410848 2015-09-02] (Realsil Semiconductor Corporation)
R2 TAOAccelerator; C:\WINDOWS\system32\Drivers\TAOAccelerator64.sys [99640 2015-12-02] (Tencent)
R1 TAOKernelDriver; C:\Windows\System32\Drivers\TAOKernel64.sys [174392 2015-12-02] (Tencent Technology(Shenzhen) Company Limited)
R3 TFsFlt; C:\Windows\System32\Drivers\TFsFltX64.sys [87864 2015-12-02] (电脑管家)
U3 TrueSight; C:\Windows\System32\drivers\TrueSight.sys [35064 2015-09-07] ()
R1 TSCPM; C:\Program Files (x86)\Tencent\QQPCMgr\10.7.16065.215\tscpm64.sys [42296 2015-12-02] (电脑管家)
S1 TSDefenseBt; C:\Program Files (x86)\Tencent\QQPCMgr\10.7.16065.215\TSDefenseBT64.sys [28472 2015-12-02] (Tencent)
R1 TSSysKit; C:\Program Files (x86)\Tencent\QQPCMgr\10.7.16065.215\TSSysKit64.sys [87352 2015-12-02] (电脑管家)
R3 t_mouse.sys; C:\Windows\system32\DRIVERS\t_mouse.sys [6144 2015-10-11] ()
S3 UdeCx; C:\Windows\System32\drivers\udecx.sys [44032 2015-07-10] ()
R3 vm331avs; C:\Windows\System32\Drivers\vm331avs.sys [802312 2015-06-12] (Vimicro Corporation)
S3 WdBoot; C:\Windows\system32\drivers\WdBoot.sys [44568 2015-07-10] (Microsoft Corporation)
S3 WdFilter; C:\Windows\system32\drivers\WdFilter.sys [291680 2015-07-10] (Microsoft Corporation)
S3 WdNisDrv; C:\Windows\System32\Drivers\WdNisDrv.sys [119648 2015-07-10] (Microsoft Corporation)
S3 wfpcapture; \SystemRoot\System32\drivers\wfpcapture.sys [X]
==================== NetSvcs (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
==================== One Month Created files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2015-12-02 22:12 - 2015-12-02 22:13 - 00023581 _____ C:\Users\Daniel\Desktop\FRST.txt
2015-12-02 22:10 - 2015-12-02 22:10 - 02350080 _____ (Farbar) C:\Users\Daniel\Desktop\FRST64.exe
2015-12-02 22:02 - 2015-10-30 18:18 - 00126776 _____ (电脑管家) C:\WINDOWS\SysWOW64\Drivers\TsFltMgr.sys
2015-12-02 22:00 - 2015-12-02 21:59 - 00099640 _____ (Tencent) C:\WINDOWS\system32\Drivers\TAOAccelerator64.sys
2015-12-02 21:59 - 2015-12-02 21:59 - 00174392 _____ (Tencent Technology(Shenzhen) Company Limited) C:\WINDOWS\system32\Drivers\TAOKernel64.sys
2015-12-02 21:59 - 2015-12-02 21:59 - 00087864 _____ (电脑管家) C:\WINDOWS\system32\Drivers\TFsFltX64.sys
2015-12-02 21:59 - 2015-12-02 21:59 - 00000000 ____D C:\Users\Daniel\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\腾讯软件
2015-12-02 21:59 - 2015-12-02 21:59 - 00000000 ____D C:\Program Files\Common Files\Tencent
2015-12-02 21:58 - 2015-12-02 22:05 - 00000000 ____D C:\Users\Daniel\AppData\Roaming\Tencent
2015-12-02 21:58 - 2015-12-02 21:59 - 00000000 ____D C:\ProgramData\Tencent
2015-12-02 21:58 - 2015-12-02 21:58 - 00000000 ____D C:\Program Files (x86)\Tencent
2015-12-02 21:35 - 2015-12-02 21:35 - 00001234 _____ C:\Users\Daniel\Desktop\全网影视.lnk
2015-12-02 21:34 - 2015-12-02 21:34 - 00001035 _____ C:\Users\Daniel\Desktop\PPS游戏大厅.lnk
2015-12-02 21:15 - 2015-12-02 21:15 - 00000000 ____D C:\Users\Daniel\.android
2015-12-02 21:14 - 2015-12-02 21:14 - 00000000 ____D C:\Users\Daniel\AppData\Roaming\ppslog
2015-12-02 21:14 - 2015-12-02 21:14 - 00000000 ____D C:\Users\Daniel\AppData\LocalLow\VirtualStore
2015-12-02 21:14 - 2015-12-02 21:14 - 00000000 ____D C:\Users\Daniel\AppData\LocalLow\Unity
2015-12-02 21:14 - 2015-12-02 21:14 - 00000000 ____D C:\Users\Daniel\AppData\Local\Unity
2015-12-02 21:14 - 2015-12-02 21:14 - 00000000 ____D C:\Users\Daniel\AppData\Local\SysassistByHotWheel
2015-12-02 21:13 - 2015-12-02 21:45 - 00000000 ____D C:\Users\Daniel\AppData\Roaming\IQIYI Video
2015-12-02 21:13 - 2015-12-02 21:36 - 00000000 ____D C:\ProgramData\IQIYI Video
2015-12-02 21:13 - 2015-12-02 21:14 - 00000000 ____D C:\IQIYI Video
2015-12-02 21:13 - 2015-12-02 21:13 - 00000000 ____D C:\Users\Public\QiYi
2015-12-02 21:11 - 2015-12-02 21:11 - 00000000 ____D C:\Program Files (x86)\baidu
2015-12-02 20:23 - 2015-12-02 20:23 - 00016148 _____ C:\WINDOWS\system32\DANIEL-LENOVO_Daniel_HistoryPrediction.bin
2015-12-02 18:18 - 2015-12-02 18:18 - 00858072 _____ C:\Users\Daniel\Desktop\mtlk.rar
2015-12-01 13:19 - 2015-12-01 13:19 - 00001085 _____ C:\Users\Daniel\Desktop\SafeQClient.lnk
2015-12-01 11:48 - 2015-12-01 11:48 - 01246406 _____ C:\Users\Daniel\Desktop\FKPIT-Projekt-č.1-zadaní-13.-Hodnocení-95-bodů-chyba-v-grafu-so-02.11.2015.rar
2015-11-30 11:14 - 2015-11-30 11:14 - 00000042 _____ C:\Users\Daniel\Desktop\vyplata listopad.txt
2015-11-28 22:19 - 2014-12-02 03:10 - 00971844 _____ C:\Users\Daniel\Desktop\Integrály komplet.pdf
2015-11-27 13:09 - 2015-11-24 11:18 - 00001153 _____ C:\Users\Daniel\Desktop\NI LabVIEW 2015 (32-bit).lnk
2015-11-27 12:44 - 2015-11-27 12:44 - 00680150 _____ C:\Users\Daniel\Desktop\Zadání semestrálního projektu MTLK.pdf
2015-11-25 17:31 - 2015-11-25 17:32 - 00000000 ___HD C:\$WINDOWS.~BT
2015-11-24 11:50 - 2015-11-24 11:50 - 00000000 ____D C:\Users\Public\Documents\National Instruments
2015-11-24 11:47 - 2015-11-24 11:47 - 00000000 ____D C:\National Instruments Downloads
2015-11-24 11:39 - 2015-12-01 21:16 - 00000000 ____D C:\Users\Daniel\Documents\LabVIEW Data
2015-11-24 11:31 - 2015-11-24 11:52 - 00003382 _____ C:\WINDOWS\System32\Tasks\NIUpdateServiceStartupTask
2015-11-24 11:31 - 2015-11-24 11:31 - 00000000 ____D C:\Users\Daniel\AppData\Local\National Instruments
2015-11-24 11:27 - 2015-11-24 12:45 - 00000000 ____D C:\ProgramData\JKI
2015-11-24 11:27 - 2015-11-24 11:27 - 00004146 _____ C:\WINDOWS\System32\Tasks\JKIUpdateTask
2015-11-24 11:27 - 2015-11-24 11:27 - 00001253 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VI Package Manager.lnk
2015-11-24 11:27 - 2015-11-24 11:27 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\JKI
2015-11-24 11:27 - 2015-11-24 11:27 - 00000000 ____D C:\Program Files (x86)\JKI
2015-11-24 11:26 - 2015-11-24 11:26 - 00000000 ____D C:\Program Files\Common Files\OPC Foundation
2015-11-24 11:24 - 2015-11-24 11:24 - 00001188 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\NI MAX.lnk
2015-11-24 11:18 - 2015-11-24 11:18 - 00001153 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\NI LabVIEW 2015 (32-bit).lnk
2015-11-24 11:15 - 2015-11-24 11:15 - 00000132 _____ C:\WINDOWS\ODBC.INI
2015-11-24 11:14 - 2015-11-24 11:14 - 00000000 ____D C:\WINDOWS\SysWOW64\cvirte
2015-11-24 11:14 - 2015-11-24 11:14 - 00000000 ____D C:\WINDOWS\system32\cvirte
2015-11-24 11:13 - 2015-11-24 11:50 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\National Instruments
2015-11-24 11:13 - 2015-11-24 11:50 - 00000000 ____D C:\Program Files\National Instruments
2015-11-24 11:13 - 2015-11-24 11:13 - 00001439 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\NI Launcher.lnk
2015-11-24 11:12 - 2015-11-24 11:50 - 00000000 ____D C:\Program Files (x86)\National Instruments
2015-11-24 11:09 - 2015-11-24 11:39 - 00000000 ____D C:\ProgramData\National Instruments
2015-11-24 10:47 - 2015-11-24 11:03 - 00000000 ____D C:\Program Files (x86)\LW
2015-11-21 12:08 - 2015-11-21 12:08 - 00000000 ____D C:\Program Files (x86)\Microsoft ASP.NET
2015-11-20 18:24 - 2015-11-20 18:24 - 00321152 _____ C:\WINDOWS\Minidump\112015-54046-01.dmp
2015-11-20 17:49 - 2015-11-20 17:50 - 00000000 ____D C:\Users\Daniel\AppData\Local\NVIDIA
2015-11-20 17:49 - 2015-11-20 17:49 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\NVIDIA Corporation
2015-11-20 17:49 - 2015-11-16 04:54 - 01828160 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvspcap64.dll
2015-11-20 17:49 - 2015-11-16 04:54 - 01756424 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvspbridge64.dll
2015-11-20 17:49 - 2015-11-16 04:54 - 01509824 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvspcap.dll
2015-11-20 17:49 - 2015-11-16 04:54 - 01316000 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvspbridge.dll
2015-11-20 17:49 - 2015-11-16 04:54 - 00112712 _____ C:\WINDOWS\system32\NvRtmpStreamer64.dll
2015-11-20 17:48 - 2015-11-20 17:48 - 00000000 ____D C:\Users\Daniel\AppData\Local\NVIDIA Corporation
2015-11-20 17:47 - 2015-11-20 17:47 - 00000000 ____D C:\WINDOWS\SysWOW64\NV
2015-11-20 17:47 - 2015-11-20 17:47 - 00000000 ____D C:\WINDOWS\system32\NV
2015-11-20 17:46 - 2015-11-16 04:54 - 00112944 _____ (Khronos Group) C:\WINDOWS\system32\OpenCL.dll
2015-11-20 17:45 - 2015-11-20 17:46 - 00000000 ____D C:\WINDOWS\LastGood.Tmp
2015-11-20 17:43 - 2015-11-20 17:43 - 00000000 ____D C:\ProgramData\Package Cache
2015-11-20 17:41 - 2015-11-17 07:27 - 00040264 _____ (NVIDIA Corporation) C:\WINDOWS\system32\Drivers\nvpciflt.sys
2015-11-20 17:41 - 2015-11-16 04:54 - 42913912 _____ C:\WINDOWS\system32\nvcompiler.dll
2015-11-20 17:41 - 2015-11-16 04:54 - 37881976 _____ C:\WINDOWS\SysWOW64\nvcompiler.dll
2015-11-20 17:41 - 2015-11-16 04:54 - 22345848 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvoglv64.dll
2015-11-20 17:41 - 2015-11-16 04:54 - 18390832 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvoglv32.dll
2015-11-20 17:41 - 2015-11-16 04:54 - 16561320 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvopencl.dll
2015-11-20 17:41 - 2015-11-16 04:54 - 15933400 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvwgf2um.dll
2015-11-20 17:41 - 2015-11-16 04:54 - 15839200 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvd3dumx.dll
2015-11-20 17:41 - 2015-11-16 04:54 - 14844112 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvcuda.dll
2015-11-20 17:41 - 2015-11-16 04:54 - 13533608 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvopencl.dll
2015-11-20 17:41 - 2015-11-16 04:54 - 12870192 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvd3dum.dll
2015-11-20 17:41 - 2015-11-16 04:54 - 12040952 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvcuda.dll
2015-11-20 17:41 - 2015-11-16 04:54 - 03540544 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvapi64.dll
2015-11-20 17:41 - 2015-11-16 04:54 - 03126800 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvapi.dll
2015-11-20 17:41 - 2015-11-16 04:54 - 02876536 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvcuvid.dll
2015-11-20 17:41 - 2015-11-16 04:54 - 02496632 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvcuvid.dll
2015-11-20 17:41 - 2015-11-16 04:54 - 01905456 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvdispco6435900.dll
2015-11-20 17:41 - 2015-11-16 04:54 - 01564792 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvdispgenco6435900.dll
2015-11-20 17:41 - 2015-11-16 04:54 - 00877688 _____ (NVIDIA Corporation) C:\WINDOWS\system32\NvFBC64.dll
2015-11-20 17:41 - 2015-11-16 04:54 - 00861816 _____ (NVIDIA Corporation) C:\WINDOWS\system32\NvIFR64.dll
2015-11-20 17:41 - 2015-11-16 04:54 - 00689784 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\NvFBC.dll
2015-11-20 17:41 - 2015-11-16 04:54 - 00674096 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\NvIFR.dll
2015-11-20 17:41 - 2015-11-16 04:54 - 00151184 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvoglshim64.dll
2015-11-20 17:41 - 2015-11-16 04:54 - 00128512 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvoglshim32.dll
2015-11-20 17:41 - 2015-11-16 04:54 - 00072504 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvaudcap64v.dll
2015-11-20 17:41 - 2015-11-16 04:54 - 00069416 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvaudcap32v.dll
2015-11-20 17:41 - 2015-11-16 04:54 - 00050472 _____ (NVIDIA Corporation) C:\WINDOWS\system32\Drivers\nvvad64v.sys
2015-11-20 16:07 - 2015-11-20 16:07 - 00000810 _____ C:\Users\Daniel\Desktop\editor – zástupce.lnk
2015-11-19 19:45 - 2015-11-19 19:45 - 00001738 _____ C:\Users\Daniel\Desktop\EXCEL – zástupce.lnk
2015-11-18 10:09 - 2015-11-18 10:09 - 00000652 _____ C:\WINDOWS\setting.ini
2015-11-18 10:09 - 2015-11-18 10:09 - 00000158 _____ C:\WINDOWS\system32\ricdb.ini
2015-11-18 10:09 - 2015-11-18 10:09 - 00000141 _____ C:\WINDOWS\setting1.ini
2015-11-18 10:09 - 2015-11-18 10:09 - 00000000 ____D C:\Users\Daniel\AppData\Local\TempDIR
2015-11-18 10:09 - 2015-11-18 10:09 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SafeQClient
2015-11-18 10:09 - 2015-11-18 10:09 - 00000000 ____D C:\Program Files (x86)\SafeQ
2015-11-17 17:15 - 2015-11-21 00:54 - 00000000 ____D C:\Users\Daniel\Desktop\foto netřiděne
2015-11-10 20:20 - 2015-11-05 06:15 - 08020832 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntoskrnl.exe
2015-11-10 20:20 - 2015-11-05 06:15 - 00541024 _____ (Microsoft Corporation) C:\WINDOWS\system32\mcupdate_GenuineIntel.dll
2015-11-10 20:20 - 2015-11-05 06:14 - 00459104 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\netio.sys
2015-11-10 20:20 - 2015-11-05 06:13 - 00577888 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\afd.sys
2015-11-10 20:20 - 2015-11-05 06:11 - 01392480 _____ (Microsoft Corporation) C:\WINDOWS\system32\LicenseManager.dll
2015-11-10 20:20 - 2015-11-05 06:06 - 03621248 _____ (Microsoft Corporation) C:\WINDOWS\system32\iertutil.dll
2015-11-10 20:20 - 2015-11-05 06:06 - 00966416 _____ (Microsoft Corporation) C:\WINDOWS\system32\twinapi.appcore.dll
2015-11-10 20:20 - 2015-11-05 06:01 - 00607408 _____ (Microsoft Corporation) C:\WINDOWS\system32\fontdrvhost.exe
2015-11-10 20:20 - 2015-11-05 05:56 - 01083072 _____ (Microsoft Corporation) C:\WINDOWS\system32\appraiser.dll
2015-11-10 20:20 - 2015-11-05 05:56 - 00116064 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\tdx.sys
2015-11-10 20:20 - 2015-11-05 05:56 - 00025280 _____ (Microsoft Corporation) C:\WINDOWS\system32\CompatTelRunner.exe
2015-11-10 20:20 - 2015-11-05 05:30 - 00961376 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\LicenseManager.dll
2015-11-10 20:20 - 2015-11-05 05:24 - 02878512 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iertutil.dll
2015-11-10 20:20 - 2015-11-05 05:23 - 00762888 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\twinapi.appcore.dll
2015-11-10 20:20 - 2015-11-05 05:23 - 00076800 _____ (Microsoft Corporation) C:\WINDOWS\system32\browserbroker.dll
2015-11-10 20:20 - 2015-11-05 05:20 - 21873664 _____ (Microsoft Corporation) C:\WINDOWS\system32\edgehtml.dll
2015-11-10 20:20 - 2015-11-05 05:18 - 24597504 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.dll
2015-11-10 20:20 - 2015-11-05 05:18 - 03248128 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.dll
2015-11-10 20:20 - 2015-11-05 05:18 - 00539728 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\fontdrvhost.exe
2015-11-10 20:20 - 2015-11-05 05:17 - 02418688 _____ (Microsoft Corporation) C:\WINDOWS\system32\MFMediaEngine.dll
2015-11-10 20:20 - 2015-11-05 05:12 - 00515072 _____ (Microsoft Corporation) C:\WINDOWS\system32\internetmail.dll
2015-11-10 20:20 - 2015-11-05 05:11 - 00333312 _____ (Microsoft Corporation) C:\WINDOWS\system32\MusUpdateHandlers.dll
2015-11-10 20:20 - 2015-11-05 05:10 - 12504064 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieframe.dll
2015-11-10 20:20 - 2015-11-05 05:10 - 02987520 _____ (Microsoft Corporation) C:\WINDOWS\system32\esent.dll
2015-11-10 20:20 - 2015-11-05 05:07 - 01068032 _____ (Microsoft Corporation) C:\WINDOWS\system32\audiosrv.dll
2015-11-10 20:20 - 2015-11-05 05:06 - 00453120 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Devices.Usb.dll
2015-11-10 20:20 - 2015-11-05 05:05 - 01602560 _____ (Microsoft Corporation) C:\WINDOWS\system32\urlmon.dll
2015-11-10 20:20 - 2015-11-05 05:05 - 00826880 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript.dll
2015-11-10 20:20 - 2015-11-05 05:03 - 02180608 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentServer.dll
2015-11-10 20:20 - 2015-11-05 05:03 - 01015808 _____ (Microsoft Corporation) C:\WINDOWS\system32\RDXService.dll
2015-11-10 20:20 - 2015-11-05 05:01 - 00949760 _____ (Microsoft Corporation) C:\WINDOWS\system32\kerberos.dll
2015-11-10 20:20 - 2015-11-05 05:01 - 00713216 _____ (Microsoft Corporation) C:\WINDOWS\system32\usermgr.dll
2015-11-10 20:20 - 2015-11-05 05:01 - 00579072 _____ (Microsoft Corporation) C:\WINDOWS\system32\winlogon.exe
2015-11-10 20:20 - 2015-11-05 04:59 - 03587072 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32kfull.sys
2015-11-10 20:20 - 2015-11-05 04:59 - 02675200 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.StateRepository.dll
2015-11-10 20:20 - 2015-11-05 04:58 - 01383936 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32kbase.sys
2015-11-10 20:20 - 2015-11-05 04:58 - 00627712 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.dll
2015-11-10 20:20 - 2015-11-05 04:56 - 01795072 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentExtensions.dll
2015-11-10 20:20 - 2015-11-05 04:55 - 00145408 _____ (Microsoft Corporation) C:\WINDOWS\system32\dssvc.dll
2015-11-10 20:20 - 2015-11-05 04:54 - 00502272 _____ (Microsoft Corporation) C:\WINDOWS\system32\dlnashext.dll
2015-11-10 20:20 - 2015-11-05 04:47 - 19326464 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtml.dll
2015-11-10 20:20 - 2015-11-05 04:42 - 02647040 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.dll
2015-11-10 20:20 - 2015-11-05 04:40 - 01918976 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MFMediaEngine.dll
2015-11-10 20:20 - 2015-11-05 04:35 - 18803712 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\edgehtml.dll
2015-11-10 20:20 - 2015-11-05 04:35 - 02639872 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\esent.dll
2015-11-10 20:20 - 2015-11-05 04:34 - 00311296 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Devices.Usb.dll
2015-11-10 20:20 - 2015-11-05 04:33 - 01380864 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\urlmon.dll
2015-11-10 20:20 - 2015-11-05 04:33 - 00650240 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript.dll
2015-11-10 20:20 - 2015-11-05 04:30 - 00767488 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\kerberos.dll
2015-11-10 20:20 - 2015-11-05 04:28 - 11262976 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieframe.dll
2015-11-10 20:20 - 2015-11-05 04:27 - 02049536 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.StateRepository.dll
2015-11-10 20:20 - 2015-11-05 04:27 - 00464896 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.dll
2015-11-10 20:20 - 2015-11-05 04:23 - 00441344 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dlnashext.dll
2015-11-10 09:48 - 2015-12-01 20:04 - 00000000 ____D C:\Users\Daniel\Desktop\OK1
2015-11-10 09:46 - 2015-11-28 15:10 - 00000000 ____D C:\Users\Daniel\Desktop\RS2
2015-11-05 11:09 - 2015-11-24 11:14 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox
==================== One Month Modified files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2015-12-02 22:12 - 2015-09-06 17:44 - 00000000 ____D C:\FRST
2015-12-02 22:04 - 2015-09-22 07:39 - 00000914 _____ C:\WINDOWS\Tasks\Adobe Flash Player Updater.job
2015-12-02 21:59 - 2015-09-01 22:48 - 00000000 ____D C:\Users\Daniel\AppData\Local\VirtualStore
2015-12-02 21:44 - 2015-09-14 07:33 - 00000988 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job
2015-12-02 21:37 - 2015-09-02 21:55 - 00000000 ____D C:\Program Files (x86)\Steam
2015-12-02 21:15 - 2015-09-01 22:48 - 00000000 ____D C:\Users\Daniel
2015-12-02 19:00 - 2015-09-20 22:03 - 00000600 _____ C:\Users\Daniel\AppData\Roaming\winscp.rnd
2015-12-02 18:52 - 2015-09-02 22:26 - 00000000 ____D C:\Users\Daniel\AppData\Roaming\TS3Client
2015-12-02 18:28 - 2015-07-10 12:04 - 00000000 ____D C:\WINDOWS\AppReadiness
2015-12-02 18:19 - 2015-09-14 07:35 - 00000000 ___RD C:\Users\Daniel\Disk Google
2015-12-02 18:18 - 2015-09-14 07:33 - 00000984 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job
2015-12-02 18:17 - 2015-07-10 13:21 - 00000006 ____H C:\WINDOWS\Tasks\SA.DAT
2015-12-02 12:22 - 2015-07-10 10:05 - 00262144 ___SH C:\WINDOWS\system32\config\BBI
2015-12-01 13:51 - 2015-09-02 22:24 - 00000000 ____D C:\Users\Daniel\AppData\Roaming\Skype
2015-11-30 23:18 - 2015-09-17 13:49 - 00000000 ____D C:\Users\Daniel\AppData\Roaming\vlc
2015-11-30 17:29 - 2015-09-11 13:13 - 00000000 ____D C:\Users\Daniel\AppData\Local\CrashDumps
2015-11-29 22:30 - 2015-07-10 12:04 - 00000000 ___HD C:\Program Files\WindowsApps
2015-11-28 23:27 - 2015-09-01 20:59 - 01762290 _____ C:\WINDOWS\system32\PerfStringBackup.INI
2015-11-28 23:27 - 2015-07-10 17:01 - 00746648 _____ C:\WINDOWS\system32\perfh005.dat
2015-11-28 23:27 - 2015-07-10 17:01 - 00149550 _____ C:\WINDOWS\system32\perfc005.dat
2015-11-28 23:27 - 2015-07-10 12:02 - 00000000 ____D C:\WINDOWS\INF
2015-11-28 21:50 - 2015-09-14 07:34 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Drive
2015-11-27 11:05 - 2015-09-03 20:08 - 00002457 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Acrobat Reader DC.lnk
2015-11-25 17:36 - 2015-09-01 21:42 - 00000000 ___DC C:\WINDOWS\Panther
2015-11-24 11:15 - 2015-07-10 10:05 - 00000000 ____D C:\Windows
2015-11-23 19:48 - 2015-09-20 11:38 - 00000000 ____D C:\ProgramData\Oracle
2015-11-23 19:48 - 2015-09-20 11:38 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java
2015-11-23 19:48 - 2015-09-20 11:38 - 00000000 ____D C:\Program Files (x86)\Java
2015-11-23 19:47 - 2015-09-20 11:38 - 00097888 _____ (Oracle Corporation) C:\WINDOWS\SysWOW64\WindowsAccessBridge-32.dll
2015-11-23 19:47 - 2015-09-20 11:38 - 00000000 ____D C:\Users\Daniel\.oracle_jre_usage
2015-11-21 23:02 - 2015-09-02 22:24 - 00000000 ____D C:\ProgramData\Skype
2015-11-20 18:24 - 2015-10-17 20:45 - 556521389 _____ C:\WINDOWS\MEMORY.DMP
2015-11-20 18:24 - 2015-10-17 20:45 - 00000000 ____D C:\WINDOWS\Minidump
2015-11-20 18:24 - 2015-07-10 13:20 - 00277600 _____ C:\WINDOWS\system32\FNTCACHE.DAT
2015-11-20 17:49 - 2015-09-01 20:47 - 00000000 ____D C:\ProgramData\NVIDIA Corporation
2015-11-20 17:49 - 2015-09-01 20:47 - 00000000 ____D C:\Program Files\NVIDIA Corporation
2015-11-20 17:49 - 2015-09-01 20:47 - 00000000 ____D C:\Program Files (x86)\NVIDIA Corporation
2015-11-20 17:47 - 2015-09-01 20:48 - 00000000 ____D C:\ProgramData\NVIDIA
2015-11-20 16:49 - 2015-07-10 12:04 - 00000000 ____D C:\WINDOWS\system32\NDF
2015-11-20 16:45 - 2014-12-07 21:54 - 00000000 ____D C:\NVIDIA
2015-11-20 12:12 - 2015-07-10 12:04 - 00000000 ____D C:\WINDOWS\rescache
2015-11-19 11:56 - 2015-09-20 21:58 - 00001117 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinSCP.lnk
2015-11-19 11:56 - 2015-09-20 21:58 - 00001059 _____ C:\Users\Daniel\Desktop\WinSCP.lnk
2015-11-19 11:56 - 2015-09-20 21:58 - 00000000 ____D C:\Program Files (x86)\WinSCP
2015-11-19 11:26 - 2015-10-13 08:38 - 00000000 ____D C:\Users\Daniel\Desktop\voip
2015-11-18 22:38 - 2015-09-02 09:42 - 00000000 ____D C:\ProgramData\Microsoft Help
2015-11-17 23:42 - 2015-10-02 10:42 - 00000000 ____D C:\Users\Daniel\Desktop\vpzma zapisek
2015-11-17 17:20 - 2015-09-02 22:11 - 00000000 ____D C:\Users\Daniel\AppData\Local\Steam
2015-11-17 07:27 - 2015-07-23 03:02 - 11228816 _____ (NVIDIA Corporation) C:\WINDOWS\system32\Drivers\nvlddmkm.sys
2015-11-16 04:54 - 2015-07-23 03:02 - 18487360 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvwgf2umx.dll
2015-11-16 04:54 - 2015-07-23 03:02 - 00539464 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvumdshimx.dll
2015-11-16 04:54 - 2015-07-23 03:02 - 00445400 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvumdshim.dll
2015-11-16 04:54 - 2015-07-23 03:02 - 00177600 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvinitx.dll
2015-11-16 04:54 - 2015-07-23 03:02 - 00155792 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvinit.dll
2015-11-16 04:54 - 2015-07-23 03:02 - 00034494 _____ C:\WINDOWS\system32\nvinfo.pb
2015-11-16 04:54 - 2015-07-10 12:00 - 00105080 _____ (Khronos Group) C:\WINDOWS\SysWOW64\opencl.dll
2015-11-14 21:13 - 2015-07-10 12:04 - 00000000 ____D C:\WINDOWS\system32\appraiser
2015-11-14 07:20 - 2015-09-01 20:48 - 06358648 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvcpl.dll
2015-11-14 07:20 - 2015-09-01 20:48 - 02983216 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvsvc64.dll
2015-11-14 07:20 - 2015-09-01 20:48 - 02554488 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvsvcr.dll
2015-11-14 07:20 - 2015-09-01 20:48 - 00938616 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvvsvc.exe
2015-11-14 07:20 - 2015-09-01 20:48 - 00523384 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nv3dappshext.dll
2015-11-14 07:20 - 2015-09-01 20:48 - 00385144 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvmctray.dll
2015-11-14 07:20 - 2015-09-01 20:48 - 00114296 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\oemdspif.dll
2015-11-14 07:20 - 2015-09-01 20:48 - 00074872 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nv3dappshextr.dll
2015-11-14 07:20 - 2015-09-01 20:48 - 00062584 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvshext.dll
2015-11-11 20:14 - 2015-07-10 11:55 - 00000000 ____D C:\WINDOWS\CbsTemp
2015-11-11 20:13 - 2015-09-05 09:45 - 00000000 ____D C:\WINDOWS\system32\MRT
2015-11-11 20:10 - 2015-09-05 09:45 - 145617392 _____ (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe
2015-11-10 21:05 - 2015-09-02 21:42 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2015-11-10 20:05 - 2015-09-22 07:39 - 00003904 _____ C:\WINDOWS\System32\Tasks\Adobe Flash Player Updater
2015-11-10 20:04 - 2015-10-17 21:04 - 05286088 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerInstaller.exe
2015-11-03 19:20 - 2015-10-05 17:35 - 00810488 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerApp.exe
2015-11-03 19:20 - 2015-10-05 17:35 - 00176632 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerCPLApp.cpl
==================== Files in the root of some directories =======
2015-04-14 17:28 - 2015-04-14 17:28 - 0004387 _____ () C:\Users\Daniel\AppData\Roaming\syznI8o9vS
2015-04-20 15:05 - 2015-04-20 15:05 - 1246720 _____ () C:\Users\Daniel\AppData\Roaming\syznI8o9vS.exe
2015-09-20 22:03 - 2015-12-02 19:00 - 0000600 _____ () C:\Users\Daniel\AppData\Roaming\winscp.rnd
2015-09-06 17:43 - 2015-09-06 17:43 - 0029696 _____ () C:\Users\Daniel\AppData\Local\MSGBOX.EXE
2015-10-14 10:40 - 2015-10-14 10:40 - 0000218 _____ () C:\Users\Daniel\AppData\Local\recently-used.xbel
2015-09-02 21:40 - 2015-09-02 21:40 - 0000000 ____H () C:\ProgramData\DP45977C.lfl
Some files in TEMP:
====================
C:\Users\Daniel\AppData\Local\Temp\2178.exe
C:\Users\Daniel\AppData\Local\Temp\DivX.Web.Player.Installer__8420_il635.exe
C:\Users\Daniel\AppData\Local\Temp\dllnt_dump.dll
C:\Users\Daniel\AppData\Local\Temp\IQIYIsetup_spl004@kb037.exe
C:\Users\Daniel\AppData\Local\Temp\jre-8u65-windows-au.exe
C:\Users\Daniel\AppData\Local\Temp\jre-8u66-windows-au.exe
C:\Users\Daniel\AppData\Local\Temp\KMS Windows 8 n 8.1 Activator__9771_il302426.exe
C:\Users\Daniel\AppData\Local\Temp\Opera_NI_stable.exe
C:\Users\Daniel\AppData\Local\Temp\PCMgr_AndroidServer.exe
C:\Users\Daniel\AppData\Local\Temp\qqpcmgr_v10.7.16065.215_71643_Silence.exe
C:\Users\Daniel\AppData\Local\Temp\setup3.exe
C:\Users\Daniel\AppData\Local\Temp\sqlite-3.8.2-x86-sqlitejdbc.dll
C:\Users\Daniel\AppData\Local\Temp\sqlite3.dll
C:\Users\Daniel\AppData\Local\Temp\~85B6.exe
C:\Users\Daniel\AppData\Local\Temp\~89FD.exe
C:\Users\Daniel\AppData\Local\Temp\~A7F.exe
C:\Users\Daniel\AppData\Local\Temp\~F35C.exe
==================== Bamital & volsnap =================
(There is no automatic fix for files that do not pass verification.)
C:\WINDOWS\system32\winlogon.exe => File is digitally signed
C:\WINDOWS\system32\wininit.exe => File is digitally signed
C:\WINDOWS\explorer.exe => File is digitally signed
C:\WINDOWS\SysWOW64\explorer.exe => File is digitally signed
C:\WINDOWS\system32\svchost.exe => File is digitally signed
C:\WINDOWS\SysWOW64\svchost.exe => File is digitally signed
C:\WINDOWS\system32\services.exe => File is digitally signed
C:\WINDOWS\system32\User32.dll => File is digitally signed
C:\WINDOWS\SysWOW64\User32.dll => File is digitally signed
C:\WINDOWS\system32\userinit.exe => File is digitally signed
C:\WINDOWS\SysWOW64\userinit.exe => File is digitally signed
C:\WINDOWS\system32\rpcss.dll => File is digitally signed
C:\WINDOWS\system32\dnsapi.dll => File is digitally signed
C:\WINDOWS\SysWOW64\dnsapi.dll => File is digitally signed
C:\WINDOWS\system32\Drivers\volsnap.sys => File is digitally signed
LastRegBack: 2015-11-23 20:20
==================== End of FRST.txt ============================
Log addiction: http://leteckaposta.cz/660268803
chtěl bych porposit o kontrolu logu. Při instalaci doplňku do mozily firefox se mi podařilo chytnout nějakou čínskou infekci.
Velice děkuji
Log:
Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version:01-12-2015
Ran by Daniel (administrator) on DANIEL-LENOVO (02-12-2015 22:12:24)
Running from C:\Users\Daniel\Desktop
Loaded Profiles: Daniel (Available Profiles: Daniel)
Platform: Windows 10 Education (X64) Language: Čeština (Česká republika)
Internet Explorer Version 11 (Default browser: FF)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/33 ... scan-tool/
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(Conexant Systems Inc.) C:\Windows\System32\CxAudMsg64.exe
(ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDService.exe
(National Instruments Corporation) C:\Windows\SysWOW64\lkads.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe
(National Instruments Corporation) C:\Program Files (x86)\National Instruments\MAX\nimxs.exe
(National Instruments Corporation) C:\Program Files (x86)\National Instruments\Shared\niauth\niauth_daemon.exe
(National Instruments Corporation) C:\Program Files (x86)\National Instruments\Shared\nisvcloc\nisvcloc.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamService.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe
(National Instruments Corporation) C:\Windows\SysWOW64\lktsrv.exe
(National Instruments, Inc.) C:\Windows\SysWOW64\lkcitdl.exe
(National Instruments Corporation) C:\Program Files (x86)\National Instruments\Shared\Security\nidmsrv.exe
(National Instruments Corporation) C:\Program Files (x86)\National Instruments\Shared\mDNS Responder\nimdnsResponder.exe
(National Instruments Corporation) C:\Program Files (x86)\National Instruments\Shared\NI Network Discovery\niDiscSvc.exe
(National Instruments Corporation) C:\Program Files (x86)\National Instruments\Shared\NI WebServer\SystemWebServer.exe
(National Instruments Corporation) C:\Program Files (x86)\National Instruments\Shared\Tagger\tagsrv.exe
(National Instruments Corporation) C:\Program Files (x86)\National Instruments\Shared\NI WebServer\ApplicationWebServer.exe
(National Instruments Corporation) C:\Program Files (x86)\National Instruments\Shared\NI WebServer\NIWebServiceContainer.exe
(National Instruments Corporation) C:\Program Files (x86)\National Instruments\Shared\NI WebServer\NIWebServiceContainer.exe
(National Instruments Corporation) C:\Program Files (x86)\National Instruments\Shared\NI WebServer\NIWebServiceContainer.exe
(National Instruments Corporation) C:\Program Files (x86)\National Instruments\Shared\NI WebServer\NIWebServiceContainer.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamNetworkService.exe
(National Instruments Corporation) C:\Program Files (x86)\National Instruments\Shared\NI WebServer\NIWebServiceContainer.exe
(ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDCtrl.exe
(Google Inc.) C:\Program Files (x86)\Google\Update\1.3.28.15\GoogleCrashHandler.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamUserAgent.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe
(ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDCtrlHelper.exe
(ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDIntelligent.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
(Google Inc.) C:\Program Files (x86)\Google\Update\1.3.28.15\GoogleCrashHandler64.exe
(Intel Corporation) C:\Windows\System32\igfxtray.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(Intel Corporation) C:\Windows\System32\igfxpers.exe
(Pixart Imaging Inc) C:\Windows\System32\TiltWheelMouse.exe
(Google) C:\Program Files (x86)\Google\Drive\googledrivesync.exe
(Vimicro) C:\Program Files (x86)\USB Camera\VM331STI.EXE
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(Google) C:\Program Files (x86)\Google\Drive\googledrivesync.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
() C:\Program Files\WindowsApps\Microsoft.Windows.Photos_15.1120.13270.0_x64__8wekyb3d8bbwe\Microsoft.Photos.exe
() C:\Program Files\WindowsApps\Microsoft.WindowsCalculator_10.1511.24020.0_x64__8wekyb3d8bbwe\Calculator.exe
( ) C:\Program Files (x86)\baidu\pps.exe
(Valve Corporation) C:\Program Files (x86)\Steam\Steam.exe
(Valve Corporation) C:\Program Files (x86)\Steam\bin\steamwebhelper.exe
(Valve Corporation) C:\Program Files (x86)\Common Files\Steam\SteamService.exe
(iQIYI.COM) C:\IQIYI Video\LStyle\QyKernel.exe
() C:\IQIYI Video\LStyle\Mobile\AndroidService.exe
(Tencent) C:\Program Files (x86)\Tencent\QQPCMgr\10.7.16065.215\TAOFrame.exe
(Tencent) C:\Program Files (x86)\Tencent\QQPCMgr\10.7.16065.215\QQPCRTP.exe
(Tencent) C:\Program Files (x86)\Tencent\QQPCMgr\10.7.16065.215\QQPCTray.exe
(Tencent) C:\Program Files (x86)\Common Files\Tencent\QQDownload\130\Tencentdl.exe
(Tencent) C:\Program Files (x86)\Tencent\QQPCMgr\10.7.16065.215\plugins\QMNetMon\QQPCNetFlow.exe
(Tencent) C:\Program Files (x86)\Tencent\QQPCMgr\10.7.16065.215\QQPCRealTimeSpeedup.exe
(Tencent) C:\Program Files (x86)\Common Files\Tencent\QQDownload\130\Tencentdl.exe
(Tencent) C:\Program Files (x86)\Tencent\QQPCMgr\10.7.16065.215\QQPCTray.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
==================== Registry (Whitelisted) ===========================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [ETDCtrl] => C:\Program Files\Elantech\ETDCtrl.exe [3743648 2015-09-05] (ELAN Microelectronics Corp.)
HKLM\...\Run: [MouseDriver] => C:\WINDOWS\system32\TiltWheelMouse.exe [241152 2015-10-11] (Pixart Imaging Inc)
HKLM\...\Run: [cAudioFilterAgent] => C:\Program Files\Conexant\cAudioFilterAgent\cAudioFilterAgent64.exe [935104 2014-11-25] (Conexant Systems, Inc.)
HKLM\...\Run: [SmartAudio] => C:\Program Files\CONEXANT\SAII\SACpl.exe [1830616 2014-04-10] (Conexant Systems, Inc.)
HKLM\...\Run: [NvBackend] => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe [2757424 2015-11-16] (NVIDIA Corporation)
HKLM\...\Run: [ShadowPlay] => "C:\WINDOWS\system32\rundll32.exe" C:\WINDOWS\system32\nvspcap64.dll,ShadowPlayOnSystemStart
HKLM-x32\...\Run: [331BigDog] => C:\Program Files (x86)\USB Camera\VM331STI.EXE [561672 2015-06-12] (Vimicro)
HKLM-x32\...\Run: [seznam-listicka-distribuce] => C:\Program Files (x86)\Seznam.cz\distribution\szninstall.exe [1062472 2013-05-16] ()
HKLM-x32\...\Run: [SafeQClient] => C:\Program Files (x86)\SafeQ\SafeQ_cli.exe [493056 2015-11-02] (VŠB-TU Ostrava)
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [596528 2015-11-09] (Oracle Corporation)
HKLM-x32\...\Run: [ QQPCTray] => C:\Program Files (x86)\Tencent\QQPCMgr\10.7.16065.215\QQPCTray.exe [355296 2015-12-02] (Tencent)
Winlogon\Notify\igfxcui: C:\WINDOWS\system32\igfxdev.dll (Intel Corporation)
HKU\S-1-5-21-2161712444-3510936251-563553130-1001\...\Run: [Steam] => C:\Program Files (x86)\Steam\steam.exe [3011152 2015-11-10] (Valve Corporation)
HKU\S-1-5-21-2161712444-3510936251-563553130-1001\...\Run: [cz.seznam.software.autoupdate] => C:\Users\Daniel\AppData\Roaming\Seznam.cz\szninstall.exe [1062472 2013-05-16] ()
HKU\S-1-5-21-2161712444-3510936251-563553130-1001\...\Run: [cz.seznam.software.szndesktop] => C:\Users\Daniel\AppData\Roaming\Seznam.cz\bin\wszndesktop.exe [103080 2015-05-26] ()
HKU\S-1-5-21-2161712444-3510936251-563553130-1001\...\Run: [GoogleDriveSync] => C:\Program Files (x86)\Google\Drive\googledrivesync.exe [22790776 2015-11-04] (Google)
HKU\S-1-5-21-2161712444-3510936251-563553130-1001\...\Run: [DAEMON Tools Lite Automount] => C:\Program Files\DAEMON Tools Lite\DTAgent.exe [4468056 2015-06-18] (Disc Soft Ltd)
HKU\S-1-5-21-2161712444-3510936251-563553130-1001\...\Run: [GSplay.exe] => C:\Users\Daniel\Desktop\GSplay.exe
HKU\S-1-5-21-2161712444-3510936251-563553130-1001\...\Run: [NIRegistrationWizard] => C:\Program Files (x86)\National Instruments\Shared\RegistrationWizard\Bin\RegistrationWizard.exe [847000 2013-04-19] ()
HKU\S-1-5-21-2161712444-3510936251-563553130-1001\...\Run: [apphide] => C:\Program Files (x86)\baidu\pps.exe [81920 2015-11-04] ( )
HKU\S-1-5-21-2161712444-3510936251-563553130-1001\...\Run: [HCDNClient] => C:\IQIYI Video\LStyle\QyKernel.exe [576104 2015-08-04] (iQIYI.COM)
HKU\S-1-5-21-2161712444-3510936251-563553130-1001\...\MountPoints2: {1dbc3f99-8472-11e5-9bd5-b888e373a893} - "E:\LG_PC_Programs.exe"
HKU\S-1-5-21-2161712444-3510936251-563553130-1001\...\MountPoints2: {9927f19a-7030-11e5-9bd0-b888e373a893} - "E:\autorun.exe"
AppInit_DLLs: C:\WINDOWS\system32\nvinitx.dll => C:\WINDOWS\system32\nvinitx.dll [177600 2015-11-16] (NVIDIA Corporation)
AppInit_DLLs-x32: C:\WINDOWS\SysWOW64\nvinit.dll => C:\WINDOWS\SysWOW64\nvinit.dll [155792 2015-11-16] (NVIDIA Corporation)
ShellIconOverlayIdentifiers: [ GoogleDriveBlacklisted] -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D42} => C:\Program Files (x86)\Google\Drive\googledrivesync64.dll [2015-11-04] (Google)
ShellIconOverlayIdentifiers: [ GoogleDriveSynced] -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D40} => C:\Program Files (x86)\Google\Drive\googledrivesync64.dll [2015-11-04] (Google)
ShellIconOverlayIdentifiers: [ GoogleDriveSyncing] -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D41} => C:\Program Files (x86)\Google\Drive\googledrivesync64.dll [2015-11-04] (Google)
ShellIconOverlayIdentifiers: [.QMDeskTopGCIcon] -> {B7667919-3765-4815-A66D-98A09BE662D6} => C:\Program Files (x86)\Tencent\QQPCMgr\10.7.16065.215\QMGCShellExt64.dll [2015-04-07] (Tencent)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\NI Error Reporting.lnk [2015-11-24]
ShortcutTarget: NI Error Reporting.lnk -> C:\Program Files (x86)\National Instruments\Shared\NI Error Reporting\nierserver.exe (National Instruments Corporation)
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
Winsock: Catalog5 07 C:\Program Files (x86)\National Instruments\Shared\mDNS Responder\nimdnsNSP.dll [26512 2014-06-06] (National Instruments Corporation)
Winsock: Catalog5-x64 07 C:\Program Files\National Instruments\Shared\mDNS Responder\nimdnsNSP.dll [28560 2014-06-06] (National Instruments Corporation)
Tcpip\Parameters: [DhcpNameServer] 10.0.0.1 10.0.1.1
Tcpip\..\Interfaces\{952e9e30-7837-4bd5-b7ce-835e1409f774}: [DhcpNameServer] 10.0.0.1 10.0.1.1
Internet Explorer:
==================
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.hao123.com/?tn=92280131_hao_pg
HKU\S-1-5-21-2161712444-3510936251-563553130-1001\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.hao123.com/?tn=92280131_hao_pg
HKU\S-1-5-21-2161712444-3510936251-563553130-1001\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://windows.microsoft.com/cs-cz/hotmail/home?ocid=iehp
SearchScopes: HKU\S-1-5-21-2161712444-3510936251-563553130-1001 -> {069202F1-27FC-4601-A5CA-41F878F17CB4} URL = hxxp://encyklopedie.seznam.cz/search?q={searchTerms}&sourceid=QuickSearch_16194
SearchScopes: HKU\S-1-5-21-2161712444-3510936251-563553130-1001 -> {0D95C45A-4BB5-40A8-AAC6-45A9A2CA3FDC} URL = hxxp://slovnik.seznam.cz/?q={searchTerms}&lang=cz_en&sourceid=QuickSearch_16194
SearchScopes: HKU\S-1-5-21-2161712444-3510936251-563553130-1001 -> {17871175-3CF6-4B2C-94D8-C8E87473DBBA} URL = hxxp://search.seznam.cz/?q={searchTerms}&sourceid=QuickSearch_16194
SearchScopes: HKU\S-1-5-21-2161712444-3510936251-563553130-1001 -> {1C10EE84-0FDE-4C21-92AA-A8E14B148BF1} URL = hxxp://tv.seznam.cz/hledej?w={searchTerms}&sourceid=QuickSearch_16194
SearchScopes: HKU\S-1-5-21-2161712444-3510936251-563553130-1001 -> {9BF95EE0-8409-4BE3-8C75-761AB9324909} URL = hxxp://slovnik.seznam.cz/?q={searchTerms}&lang=en_cz&sourceid=QuickSearch_16194
SearchScopes: HKU\S-1-5-21-2161712444-3510936251-563553130-1001 -> {A1FBF928-091F-4EA8-BD03-00673561F5CD} URL = hxxp://www.firmy.cz/?q={searchTerms}&sourceid= ... arch_16194
SearchScopes: HKU\S-1-5-21-2161712444-3510936251-563553130-1001 -> {BE5B2B07-E2DB-4C66-9A79-AA1CDA6D160B} URL = hxxp://www.zbozi.cz/?q={searchTerms}&r=campmoz ... arch_16194
SearchScopes: HKU\S-1-5-21-2161712444-3510936251-563553130-1001 -> {CE5AAD91-AB43-45DC-94F4-1C9C48ADDEF3} URL = hxxp://www.mapy.cz/?query={searchTerms}&source ... arch_16194
SearchScopes: HKU\S-1-5-21-2161712444-3510936251-563553130-1001 -> {E5F225C3-804F-47D5-81B9-AB6A482B2607} URL = hxxp://www.novinky.cz/hledej?w={searchTerms}&s ... arch_16194
BHO: 电脑管家网页防火墙 -> {7C260B4B-F7A0-40B5-B403-BEFCDC6A4C3B} -> C:\Program Files (x86)\Tencent\QQPCMgr\10.7.16065.215\TSWebMon64.dat [2015-12-02] (Tencent)
BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL [2013-03-06] (Microsoft Corporation)
BHO-x32: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files (x86)\Microsoft Office\Office14\GROOVEEX.DLL [2013-12-18] (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_66\bin\ssv.dll [2015-11-23] (Oracle Corporation)
BHO-x32: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL [2013-03-06] (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_66\bin\jp2ssv.dll [2015-11-23] (Oracle Corporation)
BHO-x32: °®ĆćŇŐÖúĘÖ -> {FB4F6285-4C32-49F2-950F-A5998F9CEC6C} -> C:\IQIYI Video\LStyle\Accelerator\IEHelper.dll [2015-08-04] (爱奇艺)
FireFox:
========
FF ProfilePath: C:\Users\Daniel\AppData\Roaming\Mozilla\Firefox\Profiles\xu00lnfi.default
FF Homepage: hxxps://www.seznam.cz/
FF Plugin: @adobe.com/FlashPlayer -> C:\WINDOWS\system32\Macromed\Flash\NPSWF64_19_0_0_245.dll [2015-11-10] ()
FF Plugin: @iqiyi.com/npclient -> C:\IQIYI Video\LStyle\npclient.dll [2015-08-04] ()
FF Plugin: @iqiyi.com/npWebPlayer -> C:\IQIYI Video\LStyle\npWebPlayer.dll [No File]
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files\Microsoft Silverlight\5.1.40728.0\npctrl.dll [2015-07-28] ( Microsoft Corporation)
FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~1\MICROS~1\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\WINDOWS\SysWOW64\Macromed\Flash\NPSWF32_19_0_0_245.dll [2015-11-10] ()
FF Plugin-x32: @iqiyi.com/npclient -> C:\IQIYI Video\LStyle\npclient.dll [2015-08-04] ()
FF Plugin-x32: @iqiyi.com/npWebPlayer -> C:\IQIYI Video\LStyle\npWebPlayer.dll [No File]
FF Plugin-x32: @java.com/DTPlugin,version=11.66.2 -> C:\Program Files (x86)\Java\jre1.8.0_66\bin\dtplugin\npDeployJava1.dll [2015-11-23] (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=11.66.2 -> C:\Program Files (x86)\Java\jre1.8.0_66\bin\plugin2\npjp2.dll [2015-11-23] (Oracle Corporation)
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files (x86)\Microsoft Silverlight\5.1.40728.0\npctrl.dll [2015-07-28] ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL [2010-03-24] (Microsoft Corporation)
FF Plugin-x32: @qq.com/QQPCMgr -> C:\Program Files (x86)\Tencent\QQPCMgr\10.7.16065.215\npQMExtensionsMozilla.dll [2015-12-02] (Tencent Technology (Shenzhen) Company Limited)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.28.15\npGoogleUpdate3.dll [2015-09-17] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.28.15\npGoogleUpdate3.dll [2015-09-17] (Google Inc.)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll [2015-09-30] (Adobe Systems Inc.)
FF Plugin HKU\S-1-5-21-2161712444-3510936251-563553130-1001: @iqiyi.com/npWebPlayer -> C:\IQIYI Video\LStyle\npWebPlayer.dll [No File]
FF Plugin HKU\S-1-5-21-2161712444-3510936251-563553130-1001: @unity3d.com/UnityPlayer,version=1.0 -> C:\Users\Daniel\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll [2014-12-05] (Unity Technologies ApS)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\nplv2014win32.dll [2015-04-30] (National Instruments)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\nplv2015win32.dll [2015-06-17] (National Instruments)
FF Extension: Adblock Plus - C:\Users\Daniel\AppData\Roaming\Mozilla\Firefox\Profiles\xu00lnfi.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2015-11-25]
==================== Services (Whitelisted) ========================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
S3 Disc Soft Lite Bus Service; C:\Program Files\DAEMON Tools Lite\DiscSoftBusService.exe [1268568 2015-06-18] (Disc Soft Ltd)
R2 ETDService; C:\Program Files\Elantech\ETDService.exe [135072 2015-09-05] (ELAN Microelectronics Corp.)
R2 GfExperienceService; C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe [1156400 2015-11-16] (NVIDIA Corporation)
R2 LkCitadelServer; C:\WINDOWS\SysWOW64\lkcitdl.exe [695136 2014-08-07] (National Instruments, Inc.)
R2 lkClassAds; C:\WINDOWS\SysWOW64\lkads.exe [53544 2015-06-01] (National Instruments Corporation)
R2 lkTimeSync; C:\WINDOWS\SysWOW64\lktsrv.exe [63792 2015-06-01] (National Instruments Corporation)
R2 mxssvr; C:\Program Files (x86)\National Instruments\MAX\nimxs.exe [84792 2015-06-12] (National Instruments Corporation)
R2 NIApplicationWebServer; C:\Program Files (x86)\National Instruments\Shared\NI WebServer\ApplicationWebServer.exe [57184 2015-06-03] (National Instruments Corporation)
S4 NIApplicationWebServer64; C:\Program Files\National Instruments\Shared\NI WebServer\ApplicationWebServer.exe [80736 2015-06-03] (National Instruments Corporation)
R2 niauth; C:\Program Files (x86)\National Instruments\Shared\niauth\niauth_daemon.exe [571712 2015-06-02] (National Instruments Corporation)
R2 NIDomainService; C:\Program Files (x86)\National Instruments\Shared\Security\nidmsrv.exe [399152 2015-06-01] (National Instruments Corporation)
S3 NILM License Manager; C:\Program Files (x86)\National Instruments\Shared\License Manager\Bin\lmgrd.exe [1427688 2010-08-02] (Macrovision Corporation)
R2 nimDNSResponder; C:\Program Files (x86)\National Instruments\Shared\mDNS Responder\nimdnsResponder.exe [320368 2014-06-06] (National Instruments Corporation)
R2 NINetworkDiscovery; C:\Program Files (x86)\National Instruments\Shared\NI Network Discovery\niDiscSvc.exe [177024 2015-06-12] (National Instruments Corporation)
R2 NiSvcLoc; C:\Program Files (x86)\National Instruments\Shared\niSvcLoc\nisvcloc.exe [89928 2015-06-02] (National Instruments Corporation)
R2 NISystemWebServer; C:\Program Files (x86)\National Instruments\Shared\NI WebServer\SystemWebServer.exe [57168 2015-06-03] (National Instruments Corporation)
R2 NITaggerService; C:\Program Files (x86)\National Instruments\Shared\Tagger\tagsrv.exe [703304 2015-06-11] (National Instruments Corporation)
R2 NvNetworkService; C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe [1872688 2015-11-16] (NVIDIA Corporation)
R3 NvStreamNetworkSvc; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamNetworkService.exe [8133424 2015-11-16] (NVIDIA Corporation)
R2 NvStreamSvc; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamService.exe [5915440 2015-11-16] (NVIDIA Corporation)
R2 QQPCRTP; C:\Program Files (x86)\Tencent\QQPCMgr\10.7.16065.215\QQPCRTP.exe [297608 2015-12-02] (Tencent)
R3 TAOFrame; C:\Program Files (x86)\Tencent\QQPCMgr\10.7.16065.215\TAOFrame.exe [293728 2015-12-02] (Tencent)
S3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [362928 2015-07-10] (Microsoft Corporation)
S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [24864 2015-07-10] (Microsoft Corporation)
===================== Drivers (Whitelisted) ==========================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R3 BCM43XX; C:\Windows\system32\DRIVERS\bcmwl63a.sys [7593176 2015-07-10] (Broadcom Corporation)
R3 dtlitescsibus; C:\Windows\System32\drivers\dtlitescsibus.sys [30264 2015-10-13] (Disc Soft Ltd)
R3 NvStreamKms; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys [19760 2015-11-16] (NVIDIA Corporation)
R3 nvvad_WaveExtensible; C:\Windows\system32\drivers\nvvad64v.sys [50472 2015-11-16] (NVIDIA Corporation)
R1 QMUdisk; C:\Program Files (x86)\Tencent\QQPCMgr\10.7.16065.215\QMUdisk64.sys [80184 2015-12-02] (Tencent)
R2 QQSysMonX64; C:\Program Files (x86)\Tencent\QQPCMgr\10.7.16065.215\QQSysMonX64.sys [127800 2015-12-02] (电脑管家)
S3 RTSUER; C:\Windows\system32\Drivers\RtsUer.sys [410848 2015-09-02] (Realsil Semiconductor Corporation)
R2 TAOAccelerator; C:\WINDOWS\system32\Drivers\TAOAccelerator64.sys [99640 2015-12-02] (Tencent)
R1 TAOKernelDriver; C:\Windows\System32\Drivers\TAOKernel64.sys [174392 2015-12-02] (Tencent Technology(Shenzhen) Company Limited)
R3 TFsFlt; C:\Windows\System32\Drivers\TFsFltX64.sys [87864 2015-12-02] (电脑管家)
U3 TrueSight; C:\Windows\System32\drivers\TrueSight.sys [35064 2015-09-07] ()
R1 TSCPM; C:\Program Files (x86)\Tencent\QQPCMgr\10.7.16065.215\tscpm64.sys [42296 2015-12-02] (电脑管家)
S1 TSDefenseBt; C:\Program Files (x86)\Tencent\QQPCMgr\10.7.16065.215\TSDefenseBT64.sys [28472 2015-12-02] (Tencent)
R1 TSSysKit; C:\Program Files (x86)\Tencent\QQPCMgr\10.7.16065.215\TSSysKit64.sys [87352 2015-12-02] (电脑管家)
R3 t_mouse.sys; C:\Windows\system32\DRIVERS\t_mouse.sys [6144 2015-10-11] ()
S3 UdeCx; C:\Windows\System32\drivers\udecx.sys [44032 2015-07-10] ()
R3 vm331avs; C:\Windows\System32\Drivers\vm331avs.sys [802312 2015-06-12] (Vimicro Corporation)
S3 WdBoot; C:\Windows\system32\drivers\WdBoot.sys [44568 2015-07-10] (Microsoft Corporation)
S3 WdFilter; C:\Windows\system32\drivers\WdFilter.sys [291680 2015-07-10] (Microsoft Corporation)
S3 WdNisDrv; C:\Windows\System32\Drivers\WdNisDrv.sys [119648 2015-07-10] (Microsoft Corporation)
S3 wfpcapture; \SystemRoot\System32\drivers\wfpcapture.sys [X]
==================== NetSvcs (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
==================== One Month Created files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2015-12-02 22:12 - 2015-12-02 22:13 - 00023581 _____ C:\Users\Daniel\Desktop\FRST.txt
2015-12-02 22:10 - 2015-12-02 22:10 - 02350080 _____ (Farbar) C:\Users\Daniel\Desktop\FRST64.exe
2015-12-02 22:02 - 2015-10-30 18:18 - 00126776 _____ (电脑管家) C:\WINDOWS\SysWOW64\Drivers\TsFltMgr.sys
2015-12-02 22:00 - 2015-12-02 21:59 - 00099640 _____ (Tencent) C:\WINDOWS\system32\Drivers\TAOAccelerator64.sys
2015-12-02 21:59 - 2015-12-02 21:59 - 00174392 _____ (Tencent Technology(Shenzhen) Company Limited) C:\WINDOWS\system32\Drivers\TAOKernel64.sys
2015-12-02 21:59 - 2015-12-02 21:59 - 00087864 _____ (电脑管家) C:\WINDOWS\system32\Drivers\TFsFltX64.sys
2015-12-02 21:59 - 2015-12-02 21:59 - 00000000 ____D C:\Users\Daniel\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\腾讯软件
2015-12-02 21:59 - 2015-12-02 21:59 - 00000000 ____D C:\Program Files\Common Files\Tencent
2015-12-02 21:58 - 2015-12-02 22:05 - 00000000 ____D C:\Users\Daniel\AppData\Roaming\Tencent
2015-12-02 21:58 - 2015-12-02 21:59 - 00000000 ____D C:\ProgramData\Tencent
2015-12-02 21:58 - 2015-12-02 21:58 - 00000000 ____D C:\Program Files (x86)\Tencent
2015-12-02 21:35 - 2015-12-02 21:35 - 00001234 _____ C:\Users\Daniel\Desktop\全网影视.lnk
2015-12-02 21:34 - 2015-12-02 21:34 - 00001035 _____ C:\Users\Daniel\Desktop\PPS游戏大厅.lnk
2015-12-02 21:15 - 2015-12-02 21:15 - 00000000 ____D C:\Users\Daniel\.android
2015-12-02 21:14 - 2015-12-02 21:14 - 00000000 ____D C:\Users\Daniel\AppData\Roaming\ppslog
2015-12-02 21:14 - 2015-12-02 21:14 - 00000000 ____D C:\Users\Daniel\AppData\LocalLow\VirtualStore
2015-12-02 21:14 - 2015-12-02 21:14 - 00000000 ____D C:\Users\Daniel\AppData\LocalLow\Unity
2015-12-02 21:14 - 2015-12-02 21:14 - 00000000 ____D C:\Users\Daniel\AppData\Local\Unity
2015-12-02 21:14 - 2015-12-02 21:14 - 00000000 ____D C:\Users\Daniel\AppData\Local\SysassistByHotWheel
2015-12-02 21:13 - 2015-12-02 21:45 - 00000000 ____D C:\Users\Daniel\AppData\Roaming\IQIYI Video
2015-12-02 21:13 - 2015-12-02 21:36 - 00000000 ____D C:\ProgramData\IQIYI Video
2015-12-02 21:13 - 2015-12-02 21:14 - 00000000 ____D C:\IQIYI Video
2015-12-02 21:13 - 2015-12-02 21:13 - 00000000 ____D C:\Users\Public\QiYi
2015-12-02 21:11 - 2015-12-02 21:11 - 00000000 ____D C:\Program Files (x86)\baidu
2015-12-02 20:23 - 2015-12-02 20:23 - 00016148 _____ C:\WINDOWS\system32\DANIEL-LENOVO_Daniel_HistoryPrediction.bin
2015-12-02 18:18 - 2015-12-02 18:18 - 00858072 _____ C:\Users\Daniel\Desktop\mtlk.rar
2015-12-01 13:19 - 2015-12-01 13:19 - 00001085 _____ C:\Users\Daniel\Desktop\SafeQClient.lnk
2015-12-01 11:48 - 2015-12-01 11:48 - 01246406 _____ C:\Users\Daniel\Desktop\FKPIT-Projekt-č.1-zadaní-13.-Hodnocení-95-bodů-chyba-v-grafu-so-02.11.2015.rar
2015-11-30 11:14 - 2015-11-30 11:14 - 00000042 _____ C:\Users\Daniel\Desktop\vyplata listopad.txt
2015-11-28 22:19 - 2014-12-02 03:10 - 00971844 _____ C:\Users\Daniel\Desktop\Integrály komplet.pdf
2015-11-27 13:09 - 2015-11-24 11:18 - 00001153 _____ C:\Users\Daniel\Desktop\NI LabVIEW 2015 (32-bit).lnk
2015-11-27 12:44 - 2015-11-27 12:44 - 00680150 _____ C:\Users\Daniel\Desktop\Zadání semestrálního projektu MTLK.pdf
2015-11-25 17:31 - 2015-11-25 17:32 - 00000000 ___HD C:\$WINDOWS.~BT
2015-11-24 11:50 - 2015-11-24 11:50 - 00000000 ____D C:\Users\Public\Documents\National Instruments
2015-11-24 11:47 - 2015-11-24 11:47 - 00000000 ____D C:\National Instruments Downloads
2015-11-24 11:39 - 2015-12-01 21:16 - 00000000 ____D C:\Users\Daniel\Documents\LabVIEW Data
2015-11-24 11:31 - 2015-11-24 11:52 - 00003382 _____ C:\WINDOWS\System32\Tasks\NIUpdateServiceStartupTask
2015-11-24 11:31 - 2015-11-24 11:31 - 00000000 ____D C:\Users\Daniel\AppData\Local\National Instruments
2015-11-24 11:27 - 2015-11-24 12:45 - 00000000 ____D C:\ProgramData\JKI
2015-11-24 11:27 - 2015-11-24 11:27 - 00004146 _____ C:\WINDOWS\System32\Tasks\JKIUpdateTask
2015-11-24 11:27 - 2015-11-24 11:27 - 00001253 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VI Package Manager.lnk
2015-11-24 11:27 - 2015-11-24 11:27 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\JKI
2015-11-24 11:27 - 2015-11-24 11:27 - 00000000 ____D C:\Program Files (x86)\JKI
2015-11-24 11:26 - 2015-11-24 11:26 - 00000000 ____D C:\Program Files\Common Files\OPC Foundation
2015-11-24 11:24 - 2015-11-24 11:24 - 00001188 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\NI MAX.lnk
2015-11-24 11:18 - 2015-11-24 11:18 - 00001153 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\NI LabVIEW 2015 (32-bit).lnk
2015-11-24 11:15 - 2015-11-24 11:15 - 00000132 _____ C:\WINDOWS\ODBC.INI
2015-11-24 11:14 - 2015-11-24 11:14 - 00000000 ____D C:\WINDOWS\SysWOW64\cvirte
2015-11-24 11:14 - 2015-11-24 11:14 - 00000000 ____D C:\WINDOWS\system32\cvirte
2015-11-24 11:13 - 2015-11-24 11:50 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\National Instruments
2015-11-24 11:13 - 2015-11-24 11:50 - 00000000 ____D C:\Program Files\National Instruments
2015-11-24 11:13 - 2015-11-24 11:13 - 00001439 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\NI Launcher.lnk
2015-11-24 11:12 - 2015-11-24 11:50 - 00000000 ____D C:\Program Files (x86)\National Instruments
2015-11-24 11:09 - 2015-11-24 11:39 - 00000000 ____D C:\ProgramData\National Instruments
2015-11-24 10:47 - 2015-11-24 11:03 - 00000000 ____D C:\Program Files (x86)\LW
2015-11-21 12:08 - 2015-11-21 12:08 - 00000000 ____D C:\Program Files (x86)\Microsoft ASP.NET
2015-11-20 18:24 - 2015-11-20 18:24 - 00321152 _____ C:\WINDOWS\Minidump\112015-54046-01.dmp
2015-11-20 17:49 - 2015-11-20 17:50 - 00000000 ____D C:\Users\Daniel\AppData\Local\NVIDIA
2015-11-20 17:49 - 2015-11-20 17:49 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\NVIDIA Corporation
2015-11-20 17:49 - 2015-11-16 04:54 - 01828160 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvspcap64.dll
2015-11-20 17:49 - 2015-11-16 04:54 - 01756424 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvspbridge64.dll
2015-11-20 17:49 - 2015-11-16 04:54 - 01509824 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvspcap.dll
2015-11-20 17:49 - 2015-11-16 04:54 - 01316000 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvspbridge.dll
2015-11-20 17:49 - 2015-11-16 04:54 - 00112712 _____ C:\WINDOWS\system32\NvRtmpStreamer64.dll
2015-11-20 17:48 - 2015-11-20 17:48 - 00000000 ____D C:\Users\Daniel\AppData\Local\NVIDIA Corporation
2015-11-20 17:47 - 2015-11-20 17:47 - 00000000 ____D C:\WINDOWS\SysWOW64\NV
2015-11-20 17:47 - 2015-11-20 17:47 - 00000000 ____D C:\WINDOWS\system32\NV
2015-11-20 17:46 - 2015-11-16 04:54 - 00112944 _____ (Khronos Group) C:\WINDOWS\system32\OpenCL.dll
2015-11-20 17:45 - 2015-11-20 17:46 - 00000000 ____D C:\WINDOWS\LastGood.Tmp
2015-11-20 17:43 - 2015-11-20 17:43 - 00000000 ____D C:\ProgramData\Package Cache
2015-11-20 17:41 - 2015-11-17 07:27 - 00040264 _____ (NVIDIA Corporation) C:\WINDOWS\system32\Drivers\nvpciflt.sys
2015-11-20 17:41 - 2015-11-16 04:54 - 42913912 _____ C:\WINDOWS\system32\nvcompiler.dll
2015-11-20 17:41 - 2015-11-16 04:54 - 37881976 _____ C:\WINDOWS\SysWOW64\nvcompiler.dll
2015-11-20 17:41 - 2015-11-16 04:54 - 22345848 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvoglv64.dll
2015-11-20 17:41 - 2015-11-16 04:54 - 18390832 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvoglv32.dll
2015-11-20 17:41 - 2015-11-16 04:54 - 16561320 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvopencl.dll
2015-11-20 17:41 - 2015-11-16 04:54 - 15933400 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvwgf2um.dll
2015-11-20 17:41 - 2015-11-16 04:54 - 15839200 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvd3dumx.dll
2015-11-20 17:41 - 2015-11-16 04:54 - 14844112 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvcuda.dll
2015-11-20 17:41 - 2015-11-16 04:54 - 13533608 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvopencl.dll
2015-11-20 17:41 - 2015-11-16 04:54 - 12870192 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvd3dum.dll
2015-11-20 17:41 - 2015-11-16 04:54 - 12040952 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvcuda.dll
2015-11-20 17:41 - 2015-11-16 04:54 - 03540544 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvapi64.dll
2015-11-20 17:41 - 2015-11-16 04:54 - 03126800 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvapi.dll
2015-11-20 17:41 - 2015-11-16 04:54 - 02876536 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvcuvid.dll
2015-11-20 17:41 - 2015-11-16 04:54 - 02496632 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvcuvid.dll
2015-11-20 17:41 - 2015-11-16 04:54 - 01905456 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvdispco6435900.dll
2015-11-20 17:41 - 2015-11-16 04:54 - 01564792 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvdispgenco6435900.dll
2015-11-20 17:41 - 2015-11-16 04:54 - 00877688 _____ (NVIDIA Corporation) C:\WINDOWS\system32\NvFBC64.dll
2015-11-20 17:41 - 2015-11-16 04:54 - 00861816 _____ (NVIDIA Corporation) C:\WINDOWS\system32\NvIFR64.dll
2015-11-20 17:41 - 2015-11-16 04:54 - 00689784 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\NvFBC.dll
2015-11-20 17:41 - 2015-11-16 04:54 - 00674096 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\NvIFR.dll
2015-11-20 17:41 - 2015-11-16 04:54 - 00151184 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvoglshim64.dll
2015-11-20 17:41 - 2015-11-16 04:54 - 00128512 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvoglshim32.dll
2015-11-20 17:41 - 2015-11-16 04:54 - 00072504 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvaudcap64v.dll
2015-11-20 17:41 - 2015-11-16 04:54 - 00069416 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvaudcap32v.dll
2015-11-20 17:41 - 2015-11-16 04:54 - 00050472 _____ (NVIDIA Corporation) C:\WINDOWS\system32\Drivers\nvvad64v.sys
2015-11-20 16:07 - 2015-11-20 16:07 - 00000810 _____ C:\Users\Daniel\Desktop\editor – zástupce.lnk
2015-11-19 19:45 - 2015-11-19 19:45 - 00001738 _____ C:\Users\Daniel\Desktop\EXCEL – zástupce.lnk
2015-11-18 10:09 - 2015-11-18 10:09 - 00000652 _____ C:\WINDOWS\setting.ini
2015-11-18 10:09 - 2015-11-18 10:09 - 00000158 _____ C:\WINDOWS\system32\ricdb.ini
2015-11-18 10:09 - 2015-11-18 10:09 - 00000141 _____ C:\WINDOWS\setting1.ini
2015-11-18 10:09 - 2015-11-18 10:09 - 00000000 ____D C:\Users\Daniel\AppData\Local\TempDIR
2015-11-18 10:09 - 2015-11-18 10:09 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SafeQClient
2015-11-18 10:09 - 2015-11-18 10:09 - 00000000 ____D C:\Program Files (x86)\SafeQ
2015-11-17 17:15 - 2015-11-21 00:54 - 00000000 ____D C:\Users\Daniel\Desktop\foto netřiděne
2015-11-10 20:20 - 2015-11-05 06:15 - 08020832 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntoskrnl.exe
2015-11-10 20:20 - 2015-11-05 06:15 - 00541024 _____ (Microsoft Corporation) C:\WINDOWS\system32\mcupdate_GenuineIntel.dll
2015-11-10 20:20 - 2015-11-05 06:14 - 00459104 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\netio.sys
2015-11-10 20:20 - 2015-11-05 06:13 - 00577888 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\afd.sys
2015-11-10 20:20 - 2015-11-05 06:11 - 01392480 _____ (Microsoft Corporation) C:\WINDOWS\system32\LicenseManager.dll
2015-11-10 20:20 - 2015-11-05 06:06 - 03621248 _____ (Microsoft Corporation) C:\WINDOWS\system32\iertutil.dll
2015-11-10 20:20 - 2015-11-05 06:06 - 00966416 _____ (Microsoft Corporation) C:\WINDOWS\system32\twinapi.appcore.dll
2015-11-10 20:20 - 2015-11-05 06:01 - 00607408 _____ (Microsoft Corporation) C:\WINDOWS\system32\fontdrvhost.exe
2015-11-10 20:20 - 2015-11-05 05:56 - 01083072 _____ (Microsoft Corporation) C:\WINDOWS\system32\appraiser.dll
2015-11-10 20:20 - 2015-11-05 05:56 - 00116064 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\tdx.sys
2015-11-10 20:20 - 2015-11-05 05:56 - 00025280 _____ (Microsoft Corporation) C:\WINDOWS\system32\CompatTelRunner.exe
2015-11-10 20:20 - 2015-11-05 05:30 - 00961376 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\LicenseManager.dll
2015-11-10 20:20 - 2015-11-05 05:24 - 02878512 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iertutil.dll
2015-11-10 20:20 - 2015-11-05 05:23 - 00762888 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\twinapi.appcore.dll
2015-11-10 20:20 - 2015-11-05 05:23 - 00076800 _____ (Microsoft Corporation) C:\WINDOWS\system32\browserbroker.dll
2015-11-10 20:20 - 2015-11-05 05:20 - 21873664 _____ (Microsoft Corporation) C:\WINDOWS\system32\edgehtml.dll
2015-11-10 20:20 - 2015-11-05 05:18 - 24597504 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.dll
2015-11-10 20:20 - 2015-11-05 05:18 - 03248128 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.dll
2015-11-10 20:20 - 2015-11-05 05:18 - 00539728 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\fontdrvhost.exe
2015-11-10 20:20 - 2015-11-05 05:17 - 02418688 _____ (Microsoft Corporation) C:\WINDOWS\system32\MFMediaEngine.dll
2015-11-10 20:20 - 2015-11-05 05:12 - 00515072 _____ (Microsoft Corporation) C:\WINDOWS\system32\internetmail.dll
2015-11-10 20:20 - 2015-11-05 05:11 - 00333312 _____ (Microsoft Corporation) C:\WINDOWS\system32\MusUpdateHandlers.dll
2015-11-10 20:20 - 2015-11-05 05:10 - 12504064 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieframe.dll
2015-11-10 20:20 - 2015-11-05 05:10 - 02987520 _____ (Microsoft Corporation) C:\WINDOWS\system32\esent.dll
2015-11-10 20:20 - 2015-11-05 05:07 - 01068032 _____ (Microsoft Corporation) C:\WINDOWS\system32\audiosrv.dll
2015-11-10 20:20 - 2015-11-05 05:06 - 00453120 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Devices.Usb.dll
2015-11-10 20:20 - 2015-11-05 05:05 - 01602560 _____ (Microsoft Corporation) C:\WINDOWS\system32\urlmon.dll
2015-11-10 20:20 - 2015-11-05 05:05 - 00826880 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript.dll
2015-11-10 20:20 - 2015-11-05 05:03 - 02180608 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentServer.dll
2015-11-10 20:20 - 2015-11-05 05:03 - 01015808 _____ (Microsoft Corporation) C:\WINDOWS\system32\RDXService.dll
2015-11-10 20:20 - 2015-11-05 05:01 - 00949760 _____ (Microsoft Corporation) C:\WINDOWS\system32\kerberos.dll
2015-11-10 20:20 - 2015-11-05 05:01 - 00713216 _____ (Microsoft Corporation) C:\WINDOWS\system32\usermgr.dll
2015-11-10 20:20 - 2015-11-05 05:01 - 00579072 _____ (Microsoft Corporation) C:\WINDOWS\system32\winlogon.exe
2015-11-10 20:20 - 2015-11-05 04:59 - 03587072 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32kfull.sys
2015-11-10 20:20 - 2015-11-05 04:59 - 02675200 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.StateRepository.dll
2015-11-10 20:20 - 2015-11-05 04:58 - 01383936 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32kbase.sys
2015-11-10 20:20 - 2015-11-05 04:58 - 00627712 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.dll
2015-11-10 20:20 - 2015-11-05 04:56 - 01795072 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentExtensions.dll
2015-11-10 20:20 - 2015-11-05 04:55 - 00145408 _____ (Microsoft Corporation) C:\WINDOWS\system32\dssvc.dll
2015-11-10 20:20 - 2015-11-05 04:54 - 00502272 _____ (Microsoft Corporation) C:\WINDOWS\system32\dlnashext.dll
2015-11-10 20:20 - 2015-11-05 04:47 - 19326464 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtml.dll
2015-11-10 20:20 - 2015-11-05 04:42 - 02647040 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.dll
2015-11-10 20:20 - 2015-11-05 04:40 - 01918976 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MFMediaEngine.dll
2015-11-10 20:20 - 2015-11-05 04:35 - 18803712 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\edgehtml.dll
2015-11-10 20:20 - 2015-11-05 04:35 - 02639872 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\esent.dll
2015-11-10 20:20 - 2015-11-05 04:34 - 00311296 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Devices.Usb.dll
2015-11-10 20:20 - 2015-11-05 04:33 - 01380864 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\urlmon.dll
2015-11-10 20:20 - 2015-11-05 04:33 - 00650240 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript.dll
2015-11-10 20:20 - 2015-11-05 04:30 - 00767488 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\kerberos.dll
2015-11-10 20:20 - 2015-11-05 04:28 - 11262976 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieframe.dll
2015-11-10 20:20 - 2015-11-05 04:27 - 02049536 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.StateRepository.dll
2015-11-10 20:20 - 2015-11-05 04:27 - 00464896 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.dll
2015-11-10 20:20 - 2015-11-05 04:23 - 00441344 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dlnashext.dll
2015-11-10 09:48 - 2015-12-01 20:04 - 00000000 ____D C:\Users\Daniel\Desktop\OK1
2015-11-10 09:46 - 2015-11-28 15:10 - 00000000 ____D C:\Users\Daniel\Desktop\RS2
2015-11-05 11:09 - 2015-11-24 11:14 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox
==================== One Month Modified files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2015-12-02 22:12 - 2015-09-06 17:44 - 00000000 ____D C:\FRST
2015-12-02 22:04 - 2015-09-22 07:39 - 00000914 _____ C:\WINDOWS\Tasks\Adobe Flash Player Updater.job
2015-12-02 21:59 - 2015-09-01 22:48 - 00000000 ____D C:\Users\Daniel\AppData\Local\VirtualStore
2015-12-02 21:44 - 2015-09-14 07:33 - 00000988 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job
2015-12-02 21:37 - 2015-09-02 21:55 - 00000000 ____D C:\Program Files (x86)\Steam
2015-12-02 21:15 - 2015-09-01 22:48 - 00000000 ____D C:\Users\Daniel
2015-12-02 19:00 - 2015-09-20 22:03 - 00000600 _____ C:\Users\Daniel\AppData\Roaming\winscp.rnd
2015-12-02 18:52 - 2015-09-02 22:26 - 00000000 ____D C:\Users\Daniel\AppData\Roaming\TS3Client
2015-12-02 18:28 - 2015-07-10 12:04 - 00000000 ____D C:\WINDOWS\AppReadiness
2015-12-02 18:19 - 2015-09-14 07:35 - 00000000 ___RD C:\Users\Daniel\Disk Google
2015-12-02 18:18 - 2015-09-14 07:33 - 00000984 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job
2015-12-02 18:17 - 2015-07-10 13:21 - 00000006 ____H C:\WINDOWS\Tasks\SA.DAT
2015-12-02 12:22 - 2015-07-10 10:05 - 00262144 ___SH C:\WINDOWS\system32\config\BBI
2015-12-01 13:51 - 2015-09-02 22:24 - 00000000 ____D C:\Users\Daniel\AppData\Roaming\Skype
2015-11-30 23:18 - 2015-09-17 13:49 - 00000000 ____D C:\Users\Daniel\AppData\Roaming\vlc
2015-11-30 17:29 - 2015-09-11 13:13 - 00000000 ____D C:\Users\Daniel\AppData\Local\CrashDumps
2015-11-29 22:30 - 2015-07-10 12:04 - 00000000 ___HD C:\Program Files\WindowsApps
2015-11-28 23:27 - 2015-09-01 20:59 - 01762290 _____ C:\WINDOWS\system32\PerfStringBackup.INI
2015-11-28 23:27 - 2015-07-10 17:01 - 00746648 _____ C:\WINDOWS\system32\perfh005.dat
2015-11-28 23:27 - 2015-07-10 17:01 - 00149550 _____ C:\WINDOWS\system32\perfc005.dat
2015-11-28 23:27 - 2015-07-10 12:02 - 00000000 ____D C:\WINDOWS\INF
2015-11-28 21:50 - 2015-09-14 07:34 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Drive
2015-11-27 11:05 - 2015-09-03 20:08 - 00002457 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Acrobat Reader DC.lnk
2015-11-25 17:36 - 2015-09-01 21:42 - 00000000 ___DC C:\WINDOWS\Panther
2015-11-24 11:15 - 2015-07-10 10:05 - 00000000 ____D C:\Windows
2015-11-23 19:48 - 2015-09-20 11:38 - 00000000 ____D C:\ProgramData\Oracle
2015-11-23 19:48 - 2015-09-20 11:38 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java
2015-11-23 19:48 - 2015-09-20 11:38 - 00000000 ____D C:\Program Files (x86)\Java
2015-11-23 19:47 - 2015-09-20 11:38 - 00097888 _____ (Oracle Corporation) C:\WINDOWS\SysWOW64\WindowsAccessBridge-32.dll
2015-11-23 19:47 - 2015-09-20 11:38 - 00000000 ____D C:\Users\Daniel\.oracle_jre_usage
2015-11-21 23:02 - 2015-09-02 22:24 - 00000000 ____D C:\ProgramData\Skype
2015-11-20 18:24 - 2015-10-17 20:45 - 556521389 _____ C:\WINDOWS\MEMORY.DMP
2015-11-20 18:24 - 2015-10-17 20:45 - 00000000 ____D C:\WINDOWS\Minidump
2015-11-20 18:24 - 2015-07-10 13:20 - 00277600 _____ C:\WINDOWS\system32\FNTCACHE.DAT
2015-11-20 17:49 - 2015-09-01 20:47 - 00000000 ____D C:\ProgramData\NVIDIA Corporation
2015-11-20 17:49 - 2015-09-01 20:47 - 00000000 ____D C:\Program Files\NVIDIA Corporation
2015-11-20 17:49 - 2015-09-01 20:47 - 00000000 ____D C:\Program Files (x86)\NVIDIA Corporation
2015-11-20 17:47 - 2015-09-01 20:48 - 00000000 ____D C:\ProgramData\NVIDIA
2015-11-20 16:49 - 2015-07-10 12:04 - 00000000 ____D C:\WINDOWS\system32\NDF
2015-11-20 16:45 - 2014-12-07 21:54 - 00000000 ____D C:\NVIDIA
2015-11-20 12:12 - 2015-07-10 12:04 - 00000000 ____D C:\WINDOWS\rescache
2015-11-19 11:56 - 2015-09-20 21:58 - 00001117 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinSCP.lnk
2015-11-19 11:56 - 2015-09-20 21:58 - 00001059 _____ C:\Users\Daniel\Desktop\WinSCP.lnk
2015-11-19 11:56 - 2015-09-20 21:58 - 00000000 ____D C:\Program Files (x86)\WinSCP
2015-11-19 11:26 - 2015-10-13 08:38 - 00000000 ____D C:\Users\Daniel\Desktop\voip
2015-11-18 22:38 - 2015-09-02 09:42 - 00000000 ____D C:\ProgramData\Microsoft Help
2015-11-17 23:42 - 2015-10-02 10:42 - 00000000 ____D C:\Users\Daniel\Desktop\vpzma zapisek
2015-11-17 17:20 - 2015-09-02 22:11 - 00000000 ____D C:\Users\Daniel\AppData\Local\Steam
2015-11-17 07:27 - 2015-07-23 03:02 - 11228816 _____ (NVIDIA Corporation) C:\WINDOWS\system32\Drivers\nvlddmkm.sys
2015-11-16 04:54 - 2015-07-23 03:02 - 18487360 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvwgf2umx.dll
2015-11-16 04:54 - 2015-07-23 03:02 - 00539464 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvumdshimx.dll
2015-11-16 04:54 - 2015-07-23 03:02 - 00445400 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvumdshim.dll
2015-11-16 04:54 - 2015-07-23 03:02 - 00177600 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvinitx.dll
2015-11-16 04:54 - 2015-07-23 03:02 - 00155792 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvinit.dll
2015-11-16 04:54 - 2015-07-23 03:02 - 00034494 _____ C:\WINDOWS\system32\nvinfo.pb
2015-11-16 04:54 - 2015-07-10 12:00 - 00105080 _____ (Khronos Group) C:\WINDOWS\SysWOW64\opencl.dll
2015-11-14 21:13 - 2015-07-10 12:04 - 00000000 ____D C:\WINDOWS\system32\appraiser
2015-11-14 07:20 - 2015-09-01 20:48 - 06358648 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvcpl.dll
2015-11-14 07:20 - 2015-09-01 20:48 - 02983216 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvsvc64.dll
2015-11-14 07:20 - 2015-09-01 20:48 - 02554488 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvsvcr.dll
2015-11-14 07:20 - 2015-09-01 20:48 - 00938616 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvvsvc.exe
2015-11-14 07:20 - 2015-09-01 20:48 - 00523384 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nv3dappshext.dll
2015-11-14 07:20 - 2015-09-01 20:48 - 00385144 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvmctray.dll
2015-11-14 07:20 - 2015-09-01 20:48 - 00114296 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\oemdspif.dll
2015-11-14 07:20 - 2015-09-01 20:48 - 00074872 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nv3dappshextr.dll
2015-11-14 07:20 - 2015-09-01 20:48 - 00062584 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvshext.dll
2015-11-11 20:14 - 2015-07-10 11:55 - 00000000 ____D C:\WINDOWS\CbsTemp
2015-11-11 20:13 - 2015-09-05 09:45 - 00000000 ____D C:\WINDOWS\system32\MRT
2015-11-11 20:10 - 2015-09-05 09:45 - 145617392 _____ (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe
2015-11-10 21:05 - 2015-09-02 21:42 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2015-11-10 20:05 - 2015-09-22 07:39 - 00003904 _____ C:\WINDOWS\System32\Tasks\Adobe Flash Player Updater
2015-11-10 20:04 - 2015-10-17 21:04 - 05286088 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerInstaller.exe
2015-11-03 19:20 - 2015-10-05 17:35 - 00810488 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerApp.exe
2015-11-03 19:20 - 2015-10-05 17:35 - 00176632 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerCPLApp.cpl
==================== Files in the root of some directories =======
2015-04-14 17:28 - 2015-04-14 17:28 - 0004387 _____ () C:\Users\Daniel\AppData\Roaming\syznI8o9vS
2015-04-20 15:05 - 2015-04-20 15:05 - 1246720 _____ () C:\Users\Daniel\AppData\Roaming\syznI8o9vS.exe
2015-09-20 22:03 - 2015-12-02 19:00 - 0000600 _____ () C:\Users\Daniel\AppData\Roaming\winscp.rnd
2015-09-06 17:43 - 2015-09-06 17:43 - 0029696 _____ () C:\Users\Daniel\AppData\Local\MSGBOX.EXE
2015-10-14 10:40 - 2015-10-14 10:40 - 0000218 _____ () C:\Users\Daniel\AppData\Local\recently-used.xbel
2015-09-02 21:40 - 2015-09-02 21:40 - 0000000 ____H () C:\ProgramData\DP45977C.lfl
Some files in TEMP:
====================
C:\Users\Daniel\AppData\Local\Temp\2178.exe
C:\Users\Daniel\AppData\Local\Temp\DivX.Web.Player.Installer__8420_il635.exe
C:\Users\Daniel\AppData\Local\Temp\dllnt_dump.dll
C:\Users\Daniel\AppData\Local\Temp\IQIYIsetup_spl004@kb037.exe
C:\Users\Daniel\AppData\Local\Temp\jre-8u65-windows-au.exe
C:\Users\Daniel\AppData\Local\Temp\jre-8u66-windows-au.exe
C:\Users\Daniel\AppData\Local\Temp\KMS Windows 8 n 8.1 Activator__9771_il302426.exe
C:\Users\Daniel\AppData\Local\Temp\Opera_NI_stable.exe
C:\Users\Daniel\AppData\Local\Temp\PCMgr_AndroidServer.exe
C:\Users\Daniel\AppData\Local\Temp\qqpcmgr_v10.7.16065.215_71643_Silence.exe
C:\Users\Daniel\AppData\Local\Temp\setup3.exe
C:\Users\Daniel\AppData\Local\Temp\sqlite-3.8.2-x86-sqlitejdbc.dll
C:\Users\Daniel\AppData\Local\Temp\sqlite3.dll
C:\Users\Daniel\AppData\Local\Temp\~85B6.exe
C:\Users\Daniel\AppData\Local\Temp\~89FD.exe
C:\Users\Daniel\AppData\Local\Temp\~A7F.exe
C:\Users\Daniel\AppData\Local\Temp\~F35C.exe
==================== Bamital & volsnap =================
(There is no automatic fix for files that do not pass verification.)
C:\WINDOWS\system32\winlogon.exe => File is digitally signed
C:\WINDOWS\system32\wininit.exe => File is digitally signed
C:\WINDOWS\explorer.exe => File is digitally signed
C:\WINDOWS\SysWOW64\explorer.exe => File is digitally signed
C:\WINDOWS\system32\svchost.exe => File is digitally signed
C:\WINDOWS\SysWOW64\svchost.exe => File is digitally signed
C:\WINDOWS\system32\services.exe => File is digitally signed
C:\WINDOWS\system32\User32.dll => File is digitally signed
C:\WINDOWS\SysWOW64\User32.dll => File is digitally signed
C:\WINDOWS\system32\userinit.exe => File is digitally signed
C:\WINDOWS\SysWOW64\userinit.exe => File is digitally signed
C:\WINDOWS\system32\rpcss.dll => File is digitally signed
C:\WINDOWS\system32\dnsapi.dll => File is digitally signed
C:\WINDOWS\SysWOW64\dnsapi.dll => File is digitally signed
C:\WINDOWS\system32\Drivers\volsnap.sys => File is digitally signed
LastRegBack: 2015-11-23 20:20
==================== End of FRST.txt ============================
Log addiction: http://leteckaposta.cz/660268803