Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version:31-12-2015
Ran by ERIK (administrator) on DOMA225 (05-01-2016 16:38:39)
Running from C:\Users\ERIK\Desktop
Loaded Profiles: ERIK (Available Profiles: ERIK & UpdatusUser & Guest)
Platform: Windows 8 Enterprise (X64) Language: English (United States)
Internet Explorer Version 10 (Default browser: Chrome)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool:
http://www.geekstogo.com/forum/topic/33 ... scan-tool/
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\Av\avgrsa.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\Av\avgcsrva.exe
() C:\Program Files (x86)\AVG Web TuneUp\WtuSystemSupport.exe
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(Adobe Systems Incorporated) C:\Program Files (x86)\Common Files\Adobe\Adobe Desktop Common\ElevationManager\AdobeUpdateService.exe
(Adobe Systems, Incorporated) C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGSService.exe
(Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\Av\avgidsagent.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\Framework\Common\avgsvca.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\Av\avgwdsvcx.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(Microsoft Corporation) C:\Program Files (x86)\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe
(Microsoft Corporation) C:\Program Files (x86)\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe
(LogMeIn, Inc.) C:\Program Files (x86)\LogMeIn Hamachi\LMIGuardianSvc.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\Av\avgnsa.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\Av\avgemca.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
() C:\Windows\SysWOW64\PnkBstrA.exe
(TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\Version9\TeamViewer_Service.exe
(TuneUp Software) C:\Program Files (x86)\TuneUp Utilities 2014\TuneUpUtilitiesService64.exe
(LogMeIn Inc.) C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe
(Valve Corporation) D:\Steam\Steam.exe
(Yandex) C:\Users\ERIK\AppData\Local\Yandex\Elements\elements.exe\8.14.0.1058\elements64.exe
(Skype Technologies S.A.) C:\Program Files (x86)\Skype\Phone\Skype.exe
(LogMeIn Inc.) C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe
(Microsoft Corporation) C:\Program Files (x86)\Microsoft Office\Office14\ONENOTEM.EXE
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(Apple Inc.) C:\Program Files (x86)\iTunes\iTunesHelper.exe
() C:\Program Files (x86)\Gaming Keyboard\Monitor.EXE
(Wondershare) C:\Program Files (x86)\Common Files\Wondershare\Wondershare Helper Compact\WSHelper.exe
(Power Software Ltd) C:\Program Files\PowerISO\PWRISOVM.EXE
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\Framework\Common\avguix.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\Av\avgui.exe
(Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe
() C:\Program Files (x86)\Gaming Keyboard\OSD.exe
(TuneUp Software) C:\Program Files (x86)\TuneUp Utilities 2014\TuneUpUtilitiesApp64.exe
(Microsoft Corporation) C:\Windows\System32\msiexec.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Valve Corporation) D:\Steam\bin\steamwebhelper.exe
(Valve Corporation) C:\Program Files (x86)\Common Files\Steam\SteamService.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
==================== Registry (Whitelisted) ===========================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe [7199448 2013-10-01] (Realtek Semiconductor)
HKLM\...\Run: [V0700Pin.dll] => RunDLL32.exe V0700Pin.dll,RunDLL32EP 514,/d:2
HKLM\...\Run: [AdobeAAMUpdater-1.0] => C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [508104 2015-10-30] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959904 2013-11-21] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [V0700Mon.exe] => C:\Windows\V0700Mon.exe
HKLM-x32\...\Run: [BlueStacks Agent] => C:\Program Files (x86)\BlueStacks\HD-Agent.exe
HKLM-x32\...\Run: [Adobe Creative Cloud] => C:\Program Files (x86)\Adobe\Adobe Creative Cloud\ACC\Creative Cloud.exe [2304688 2015-12-15] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [seznam-listicka-distribuce] => C:\Program Files (x86)\Seznam.cz\distribution\szninstall.exe [1062472 2013-05-16] ()
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [256896 2014-07-25] (Oracle Corporation)
HKLM-x32\...\Run: [iTunesHelper] => C:\Program Files (x86)\iTunes\iTunesHelper.exe [157480 2014-10-15] (Apple Inc.)
HKLM-x32\...\Run: [Gaming Keyboard] => C:\Program Files (x86)\Gaming Keyboard\Monitor.exe [479232 2014-01-16] ()
HKLM-x32\...\Run: [Wondershare Helper Compact.exe] => C:\Program Files (x86)\Common Files\Wondershare\Wondershare Helper Compact\WSHelper.exe [2087264 2014-09-11] (Wondershare)
HKLM-x32\...\Run: [PWRISOVM.EXE] => C:\Program Files\PowerISO\PWRISOVM.EXE [408888 2015-06-08] (Power Software Ltd)
HKLM-x32\...\Run: [AvgUi] => C:\Program Files (x86)\AVG\Framework\Common\avguix.exe [1136552 2015-11-12] (AVG Technologies CZ, s.r.o.)
HKLM-x32\...\Run: [AVG_UI] => C:\Program Files (x86)\AVG\Av\avgui.exe [3855272 2015-11-20] (AVG Technologies CZ, s.r.o.)
HKLM-x32\...\Run: [LogMeIn Hamachi Ui] => C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe [5565448 2015-11-12] (LogMeIn Inc.)
HKU\S-1-5-21-2796967165-1696306274-2783790974-1001\...\Run: [DAEMON Tools Lite] => D:\hry\DAEMON Tools Lite\DTLite.exe [3696912 2014-03-04] (Disc Soft Ltd)
HKU\S-1-5-21-2796967165-1696306274-2783790974-1001\...\Run: [EADM] => C:\Program Files (x86)\Origin\Origin.exe [3638256 2015-10-23] (Electronic Arts)
HKU\S-1-5-21-2796967165-1696306274-2783790974-1001\...\Run: [cz.seznam.software.autoupdate] => C:\Users\ERIK\AppData\Roaming\Seznam.cz\szninstall.exe [1062472 2013-05-16] ()
HKU\S-1-5-21-2796967165-1696306274-2783790974-1001\...\Run: [cz.seznam.software.szndesktop] => C:\Users\ERIK\AppData\Roaming\Seznam.cz\bin\wszndesktop.exe [92664 2013-04-12] ()
HKU\S-1-5-21-2796967165-1696306274-2783790974-1001\...\Run: [Facebook Update] => C:\Users\ERIK\AppData\Local\Facebook\Update\FacebookUpdate.exe [138096 2014-08-22] (Facebook Inc.)
HKU\S-1-5-21-2796967165-1696306274-2783790974-1001\...\Run: [GoogleChromeAutoLaunch_5998AE56BE14438E63B1EE3391313A39] => C:\Program Files (x86)\Google\Chrome\Application\chrome.exe [741704 2015-12-11] (Google Inc.)
HKU\S-1-5-21-2796967165-1696306274-2783790974-1001\...\Run: [KSS] => "C:\Program Files (x86)\Kaspersky Lab\Kaspersky Security Scan\kss.exe" autorun
HKU\S-1-5-21-2796967165-1696306274-2783790974-1001\...\Run: [Steam] => D:\Steam\steam.exe [3013712 2015-12-14] (Valve Corporation)
HKU\S-1-5-21-2796967165-1696306274-2783790974-1001\...\Run: [YandexElements] => C:\Users\ERIK\AppData\Local\Yandex\Elements\elements.exe\8.14.0.1058\elements64.exe [1589536 2015-10-30] (Yandex)
HKU\S-1-5-21-2796967165-1696306274-2783790974-1001\...\Run: [Skype] => C:\Program Files (x86)\Skype\Phone\Skype.exe [50749056 2015-12-08] (Skype Technologies S.A.)
HKU\S-1-5-21-2796967165-1696306274-2783790974-1001\...\Policies\Explorer: [NoDriveTypeAutoRun] 0x95000000
ShellIconOverlayIdentifiers: [ AccExtIco1] -> {AB9CF9F8-8A96-4F9D-BF21-CE85714C3A47} => C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CoreSyncExtension\CoreSync_x64.dll [2015-11-14] ()
ShellIconOverlayIdentifiers: [ AccExtIco2] -> {853B7E05-C47D-4985-909A-D0DC5C6D7303} => C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CoreSyncExtension\CoreSync_x64.dll [2015-11-14] ()
ShellIconOverlayIdentifiers: [ AccExtIco3] -> {42D38F2E-98E9-4382-B546-E24E4D6D04BB} => C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CoreSyncExtension\CoreSync_x64.dll [2015-11-14] ()
ShellIconOverlayIdentifiers: [###MegaShellExtPending] -> {056D528D-CE28-4194-9BA3-BA2E9197FF8C} => C:\Users\ERIK\AppData\Local\MEGAsync\ShellExtX64.dll [2014-05-01] ()
ShellIconOverlayIdentifiers: [###MegaShellExtSynced] -> {05B38830-F4E9-4329-978B-1DD28605D202} => C:\Users\ERIK\AppData\Local\MEGAsync\ShellExtX64.dll [2014-05-01] ()
ShellIconOverlayIdentifiers: [###MegaShellExtSyncing] -> {0596C850-7BDD-4C9D-AFDF-873BE6890637} => C:\Users\ERIK\AppData\Local\MEGAsync\ShellExtX64.dll [2014-05-01] ()
ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => No File
ShellIconOverlayIdentifiers: [DropboxExt1] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\ERIK\AppData\Roaming\Dropbox\bin\DropboxExt64.22.dll [2013-09-11] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [DropboxExt2] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\ERIK\AppData\Roaming\Dropbox\bin\DropboxExt64.22.dll [2013-09-11] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [DropboxExt3] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\ERIK\AppData\Roaming\Dropbox\bin\DropboxExt64.22.dll [2013-09-11] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [DropboxExt4] -> {FB314EDC-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\ERIK\AppData\Roaming\Dropbox\bin\DropboxExt64.22.dll [2013-09-11] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [###MegaShellExtPending] -> {056D528D-CE28-4194-9BA3-BA2E9197FF8C} => C:\Users\ERIK\AppData\Local\MEGAsync\ShellExtX32.dll [2014-05-01] ()
ShellIconOverlayIdentifiers-x32: [###MegaShellExtSynced] -> {05B38830-F4E9-4329-978B-1DD28605D202} => C:\Users\ERIK\AppData\Local\MEGAsync\ShellExtX32.dll [2014-05-01] ()
ShellIconOverlayIdentifiers-x32: [###MegaShellExtSyncing] -> {0596C850-7BDD-4C9D-AFDF-873BE6890637} => C:\Users\ERIK\AppData\Local\MEGAsync\ShellExtX32.dll [2014-05-01] ()
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\McAfee Security Scan Plus.lnk [2015-11-06]
ShortcutTarget: McAfee Security Scan Plus.lnk -> C:\Program Files (x86)\McAfee Security Scan\3.11.163\SSScheduler.exe (McAfee, Inc.)
Startup: C:\Users\ERIK\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Výřezy obrazovky a spuštění aplikace OneNote 2010.lnk [2015-01-24]
ShortcutTarget: Výřezy obrazovky a spuštění aplikace OneNote 2010.lnk -> C:\Program Files (x86)\Microsoft Office\Office14\ONENOTEM.EXE (Microsoft Corporation)
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
ProxyServer: [S-1-5-21-2796967165-1696306274-2783790974-1001] => http=127.0.0.1:14326;https=127.0.0.1:14326
Tcpip\..\Interfaces\{A45B3B47-1DEE-488D-8E7A-98105E31809C}: [DhcpNameServer] 7.254.254.254
Tcpip\..\Interfaces\{D7BF9759-483B-4DF8-9D39-8EE151365322}: [NameServer] 8.8.8.8,8.8.4.4
Tcpip\..\Interfaces\{D7BF9759-483B-4DF8-9D39-8EE151365322}: [DhcpNameServer] 217.30.64.53 217.30.64.54
Internet Explorer:
==================
HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer: Restriction <======= ATTENTION
HKU\S-1-5-21-2796967165-1696306274-2783790974-1001\SOFTWARE\Policies\Microsoft\Internet Explorer: Restriction <======= ATTENTION
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = about:blank
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = hxxp://
www.bing.com/search?q={searchTerms}&FORM=AVASDF&PC=AV01
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL =
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL =
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://
www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://
www.microsoft.com/isapi/redir.dll?prd=ie&ar=msnhome
HKU\S-1-5-21-2796967165-1696306274-2783790974-1001\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://
www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
HKU\S-1-5-21-2796967165-1696306274-2783790974-1001\Software\Microsoft\Internet Explorer\Main,Start Page = hxxps://mysearch.avg.com/?cid={C7296285-8EF6-429D-A007-DB4C0E17E2CD}&mid=fe556fa2a07347d29dcbc593af903d96-3d3620fc598cb7aeac6614661c0681c3d61b8456&lang=cs&ds=AVG&coid=avgtbavg&cmpid=1215av&pr=fr&d=2015-12-26 19:08:59&v=4.2.4.155&pid=wtu&sg=&sap=hp
SearchScopes: HKLM-x32 -> DefaultScope {632F07F3-19A1-4d16-A23F-E6CE9486BAB5} URL = hxxp://
www.bing.com/search?q={searchTerms}&FORM=AVASDF&PC=AV01
SearchScopes: HKLM-x32 -> {632F07F3-19A1-4d16-A23F-E6CE9486BAB5} URL = hxxp://
www.bing.com/search?q={searchTerms}&FORM=AVASDF&PC=AV01
SearchScopes: HKU\S-1-5-21-2796967165-1696306274-2783790974-1001 -> DefaultScope {632F07F3-19A1-4d16-A23F-E6CE9486BAB5} URL = hxxp://search.seznam.cz/?sourceid=quicksearch_6826&q={searchTerms}
SearchScopes: HKU\S-1-5-21-2796967165-1696306274-2783790974-1001 -> 16944E13E82DEFA97D39592013C2B7A8 URL = hxxp://
www.firmy.cz/phr/{searchTerms}
SearchScopes: HKU\S-1-5-21-2796967165-1696306274-2783790974-1001 -> 1AB234BDEAB8D862D0356D5587B0A9B4 URL = hxxp://
www.bing.com/search?q={searchTerms}&FORM=AVASDF&PC=AV01
SearchScopes: HKU\S-1-5-21-2796967165-1696306274-2783790974-1001 -> 33D267CDA73706E77445E11F79A59BC4 URL = hxxp://
www.mapy.cz/?sourceid=quicksearch_6826& ... earchTerms}
SearchScopes: HKU\S-1-5-21-2796967165-1696306274-2783790974-1001 -> D409C7645CA7CA4C24B1AFA73B1AEF36 URL = hxxp://videa.seznam.cz/?q={searchTerms}
SearchScopes: HKU\S-1-5-21-2796967165-1696306274-2783790974-1001 -> DF91290F8D6EC8584060B5957DE2FB6C URL = hxxp://
www.zbozi.cz/?sourceid=quicksearch_6826&q={searchTerms}
SearchScopes: HKU\S-1-5-21-2796967165-1696306274-2783790974-1001 -> {632F07F3-19A1-4d16-A23F-E6CE9486BAB5} URL = hxxp://search.seznam.cz/?sourceid=quicksearch_6826&q={searchTerms}
BHO: Skype Click to Call for Internet Explorer -> {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} -> C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll [2015-10-12] (Microsoft Corporation)
BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL [2013-03-06] (Microsoft Corporation)
BHO: Визуальные закладки -> {D5FEC983-01DB-414A-9456-AF95AC9ED7B5} -> C:\Program Files (x86)\Yandex\FastDial\fastdial64host.dll => No File
BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre7\bin\ssv.dll [2014-10-07] (Oracle Corporation)
BHO-x32: Skype Click to Call for Internet Explorer -> {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} -> C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll [2015-10-12] (Microsoft Corporation)
BHO-x32: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL [2013-03-06] (Microsoft Corporation)
BHO-x32: Визуальные закладки -> {D5FEC983-01DB-414A-9456-AF95AC9ED7B5} -> C:\Program Files (x86)\Yandex\FastDial\fastdialhost.dll => No File
BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll [2014-10-07] (Oracle Corporation)
Toolbar: HKLM - Элементы Яндекса - {91397D20-1446-11D4-8AF4-0040CA1127B6} - C:\Program Files (x86)\Yandex\Elements\bartab64host.dll No File
Toolbar: HKLM-x32 - Элементы Яндекса - {91397D20-1446-11D4-8AF4-0040CA1127B6} - C:\Program Files (x86)\Yandex\Elements\bartabhost.dll No File
Toolbar: HKU\S-1-5-21-2796967165-1696306274-2783790974-1001 -> Элементы Яндекса - {91397D20-1446-11D4-8AF4-0040CA1127B6} - C:\Program Files (x86)\Yandex\Elements\bartab64host.dll No File
Handler: skypec2c - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll [2015-10-12] (Microsoft Corporation)
Handler-x32: skypec2c - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll [2015-10-12] (Microsoft Corporation)
FireFox:
========
FF ProfilePath: C:\Users\ERIK\AppData\Roaming\Mozilla\Firefox\Profiles\nahd6ha2.default
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_20_0_0_267.dll [2015-12-28] ()
FF Plugin: @esn/npbattlelog,version=2.6.2 -> C:\Program Files (x86)\Battlelog Web Plugins\2.6.2\npbattlelogx64.dll [No File]
FF Plugin: @esn/npbattlelog,version=2.7.0 -> C:\Program Files (x86)\Battlelog Web Plugins\2.7.0\npbattlelogx64.dll [No File]
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files\Microsoft Silverlight\5.1.41105.0\npctrl.dll [2015-11-04] ( Microsoft Corporation)
FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~1\MICROS~1\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation)
FF Plugin: adobe.com/AdobeAAMDetect -> C:\Program Files (x86)\Adobe\Adobe Creative Cloud\Utils\npAdobeAAMDetect64.dll [2015-12-15] (Adobe Systems)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_20_0_0_267.dll [2015-12-28] ()
FF Plugin-x32: @Apple.com/iTunes,version=1.0 -> C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll [2014-02-18] ()
FF Plugin-x32: @esn/npbattlelog,version=2.6.2 -> C:\Program Files (x86)\Battlelog Web Plugins\2.6.2\npbattlelog.dll [No File]
FF Plugin-x32: @esn/npbattlelog,version=2.7.0 -> C:\Program Files (x86)\Battlelog Web Plugins\2.7.0\npbattlelog.dll [No File]
FF Plugin-x32: @java.com/DTPlugin,version=10.67.2 -> C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll [2014-10-07] (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=10.67.2 -> C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll [2014-10-07] (Oracle Corporation)
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files (x86)\Microsoft Silverlight\5.1.41105.0\npctrl.dll [2015-11-04] ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL [2010-03-24] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=16.4.3528.0331 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2014-03-31] (Microsoft Corporation)
FF Plugin-x32: @nvidia.com/3DVision -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll [2013-10-23] (NVIDIA Corporation)
FF Plugin-x32: @nvidia.com/3DVisionStreaming -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll [2013-10-23] (NVIDIA Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.29.1\npGoogleUpdate3.dll [2015-12-03] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.29.1\npGoogleUpdate3.dll [2015-12-03] (Google Inc.)
FF Plugin-x32: @videolan.org/vlc,version=2.1.2 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2013-12-09] (VideoLAN)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll [2014-08-05] (Adobe Systems Inc.)
FF Plugin-x32: adobe.com/AdobeAAMDetect -> C:\Program Files (x86)\Adobe\Adobe Creative Cloud\Utils\npAdobeAAMDetect32.dll [2015-12-15] (Adobe Systems)
FF Plugin HKU\S-1-5-21-2796967165-1696306274-2783790974-1001: @Skype Limited.com/Facebook Video Calling Plugin -> C:\Users\ERIK\AppData\Local\Facebook\Video\Skype\npFacebookVideoCalling.dll [2014-07-24] (Skype Limited)
FF Plugin HKU\S-1-5-21-2796967165-1696306274-2783790974-1001: @unity3d.com/UnityPlayer,version=1.0 -> C:\Users\ERIK\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll [2015-10-20] (Unity Technologies ApS)
FF SearchPlugin: C:\Users\ERIK\AppData\Roaming\Mozilla\Firefox\Profiles\nahd6ha2.default\searchplugins\firmy.cz-080222.xml [2015-10-27]
FF SearchPlugin: C:\Users\ERIK\AppData\Roaming\Mozilla\Firefox\Profiles\nahd6ha2.default\searchplugins\mapy.cz-080222.xml [2015-10-27]
FF SearchPlugin: C:\Users\ERIK\AppData\Roaming\Mozilla\Firefox\Profiles\nahd6ha2.default\searchplugins\seznam.cz-080222.xml [2015-10-27]
FF SearchPlugin: C:\Users\ERIK\AppData\Roaming\Mozilla\Firefox\Profiles\nahd6ha2.default\searchplugins\videa.seznam.cz-080222.xml [2015-10-27]
FF SearchPlugin: C:\Users\ERIK\AppData\Roaming\Mozilla\Firefox\Profiles\nahd6ha2.default\searchplugins\zbozi.cz-080222.xml [2015-10-27]
FF HKU\S-1-5-21-2796967165-1696306274-2783790974-1001\...\Firefox\Extensions: [{B85CB4C6-D9D8-F0A8-369B-3B13E463B8E8}] - C:\Program Files (x86)\BlockAndSurf-soft\171.xpi => not found
Chrome:
=======
CHR HomePage: Default -> search.ask.com/?gct=hp
CHR StartupUrls: Default -> "","
www.google.com"
CHR Plugin: (Widevine Content Decryption Module) - C:\Users\ERIK\AppData\Local\Google\Chrome\User Data\WidevineCDM\1.4.8.824\_platform_specific\win_x86\widevinecdmadapter.dll => No File
CHR Plugin: (Shockwave Flash) - C:\Program Files (x86)\Google\Chrome\Application\47.0.2526.106\PepperFlash\pepflashplayer.dll ()
CHR Profile: C:\Users\ERIK\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (Seznam Lištička - Email) - C:\Users\ERIK\AppData\Local\Google\Chrome\User Data\Default\Extensions\bgjpfhpjcgdppjbgnpnjllokbmcdllig [2015-02-18]
CHR Extension: (Seznam Lištička - Slovník) - C:\Users\ERIK\AppData\Local\Google\Chrome\User Data\Default\Extensions\blmojkbhnkkphngknkmgccmlenfaelkd [2014-07-22]
CHR Extension: (KB SSL Enforcer) - C:\Users\ERIK\AppData\Local\Google\Chrome\User Data\Default\Extensions\flcpelgcagfhfoegekianiofphddckof [2015-01-24]
CHR Extension: (AdBlock) - C:\Users\ERIK\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom [2015-12-03]
CHR Extension: (Anonymous) - C:\Users\ERIK\AppData\Local\Google\Chrome\User Data\Default\Extensions\iceilgfippckmaabaghcnfmieeccoipf [2015-07-08]
CHR Extension: (Facebook Invite All) - C:\Users\ERIK\AppData\Local\Google\Chrome\User Data\Default\Extensions\inmmhkeajgflmokoaaoadgkhhmibjbpj [2015-11-09]
CHR Extension: (Skype) - C:\Users\ERIK\AppData\Local\Google\Chrome\User Data\Default\Extensions\lifbcibllhkdhoafpjfnlhfpfgnpldfl [2015-12-17]
CHR Extension: (Platby Internetového obchodu Chrome) - C:\Users\ERIK\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2015-07-30]
CHR Extension: (Seznam Lištička - Rychlá volba) - C:\Users\ERIK\AppData\Local\Google\Chrome\User Data\Default\Extensions\olfeabkoenfaoljndfecamgilllcpiak [2015-10-28]
CHR Extension: (Vizuální záložky) - C:\Users\ERIK\AppData\Local\Google\Chrome\User Data\Default\Extensions\pchfckkccldkbclgdepkaonamkignanh [2015-12-08]
CHR HKLM\...\Chrome\Extension: [aaaaaejaghnbcjilindpkgmcmdflpgjf] - C:\ProgramData\AskPartnerNetwork\Toolbar\Shared\CRX\aaaaaejaghnbcjilindpkgmcmdflpgjf.crx <not found>
CHR HKLM\...\Chrome\Extension: [aaaaahaeginbdcckocjkhbciadcafnep] - C:\ProgramData\AskPartnerNetwork\Toolbar\Shared\CRX\aaaaahaeginbdcckocjkhbciadcafnep.crx <not found>
CHR HKLM\...\Chrome\Extension: [pljcgbedjplidkdjahbaalanadmjfgop] - C:\ProgramData\AskPartnerNetwork\Toolbar\ORJ-V7C\CRX\ToolbarCR.crx <not found>
CHR HKLM-x32\...\Chrome\Extension: [aaaaaejaghnbcjilindpkgmcmdflpgjf] - C:\ProgramData\AskPartnerNetwork\Toolbar\Shared\CRX\aaaaaejaghnbcjilindpkgmcmdflpgjf.crx <not found>
CHR HKLM-x32\...\Chrome\Extension: [aaaaahaeginbdcckocjkhbciadcafnep] - C:\ProgramData\AskPartnerNetwork\Toolbar\Shared\CRX\aaaaahaeginbdcckocjkhbciadcafnep.crx <not found>
CHR HKLM-x32\...\Chrome\Extension: [bopakagnckmlgajfccecajhnimjiiedh] - hxxp://clients2.google.com/service/update2/crx
CHR HKLM-x32\...\Chrome\Extension: [lifbcibllhkdhoafpjfnlhfpfgnpldfl] - C:\Program Files (x86)\Skype\Toolbars\ChromeExtension\skype_chrome_extension.crx [2015-10-12]
CHR HKLM-x32\...\Chrome\Extension: [pchfckkccldkbclgdepkaonamkignanh] - hxxp://clients2.google.com/service/update2/crx
CHR HKLM-x32\...\Chrome\Extension: [pljcgbedjplidkdjahbaalanadmjfgop] - C:\ProgramData\AskPartnerNetwork\Toolbar\ORJ-V7C\CRX\ToolbarCR.crx <not found>
==================== Services (Whitelisted) ========================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R2 AdobeUpdateService; C:\Program Files (x86)\Common Files\Adobe\Adobe Desktop Common\ElevationManager\AdobeUpdateService.exe [683696 2015-11-16] (Adobe Systems Incorporated)
R2 AGSService; C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGSService.exe [2016448 2015-11-25] (Adobe Systems, Incorporated)
S3 AvgAMPS; C:\Program Files (x86)\AVG\Av\avgamps.exe [615584 2015-11-20] (AVG Technologies CZ, s.r.o.)
R2 AVGIDSAgent; C:\Program Files (x86)\AVG\Av\avgidsagent.exe [3857272 2015-11-20] (AVG Technologies CZ, s.r.o.)
R2 avgsvc; C:\Program Files (x86)\AVG\Framework\Common\avgsvca.exe [1046952 2015-11-12] (AVG Technologies CZ, s.r.o.)
R2 avgwd; C:\Program Files (x86)\AVG\Av\avgwdsvcx.exe [579776 2015-11-20] (AVG Technologies CZ, s.r.o.)
R2 c2cautoupdatesvc; C:\Program Files (x86)\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe [1433216 2015-10-12] (Microsoft Corporation)
R2 c2cpnrsvc; C:\Program Files (x86)\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe [1773696 2015-10-12] (Microsoft Corporation)
S3 EasyAntiCheat; C:\Windows\SysWOW64\EasyAntiCheat.exe [236840 2015-04-13] (EasyAntiCheat Ltd)
R2 LMIGuardianSvc; C:\Program Files (x86)\LogMeIn Hamachi\LMIGuardianSvc.exe [417552 2015-11-12] (LogMeIn, Inc.)
S2 MBAMScheduler; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe [1809720 2014-05-12] (Malwarebytes Corporation)
S2 MBAMService; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe [860472 2014-05-12] (Malwarebytes Corporation)
S3 McComponentHostService; C:\Program Files (x86)\McAfee Security Scan\3.11.163\McCHSvc.exe [235696 2015-07-31] (McAfee, Inc.)
S3 Origin Client Service; C:\Program Files (x86)\Origin\OriginClientService.exe [2099208 2015-10-23] (Electronic Arts)
R2 PnkBstrA; C:\Windows\system32\PnkBstrA.exe [76152 2015-03-23] ()
R2 PnkBstrA; C:\Windows\SysWOW64\PnkBstrA.exe [75136 2015-04-06] ()
S3 Survarium-Steam Update Service; D:\hry\SteamLibrary\steamapps\common\Survarium\game\binaries\x86\survarium_service.exe [76408 2015-04-14] ()
R2 TuneUp.UtilitiesSvc; C:\Program Files (x86)\TuneUp Utilities 2014\TuneUpUtilitiesService64.exe [2145080 2014-07-16] (TuneUp Software)
S3 TunngleService; C:\Program Files (x86)\Tunngle\TnglCtrl.exe [805840 2015-09-26] (Tunngle.net GmbH) [File not signed]
S3 VSStandardCollectorService140; C:\Program Files (x86)\Microsoft Visual Studio 14.0\Team Tools\DiagnosticsHub\Collector\StandardCollector.Service.exe [52968 2015-07-07] (Microsoft Corporation)
S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [16056 2015-07-06] (Microsoft Corporation)
R2 WtuSystemSupport; C:\Program Files (x86)\AVG Web TuneUp\WtuSystemSupport.exe [1164688 2015-12-26] ()
S2 BstHdAndroidSvc; "C:\Program Files (x86)\BlueStacks\HD-Service.exe" BstHdAndroidSvc Android [X]
S2 BstHdLogRotatorSvc; C:\Program Files (x86)\BlueStacks\HD-LogRotatorService.exe [X]
S2 BstHdUpdaterSvc; C:\Program Files (x86)\BlueStacks\HD-UpdaterService.exe [X]
===================== Drivers (Whitelisted) ==========================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R3 AU8168; C:\Windows\system32\DRIVERS\au630x64.sys [792648 2013-09-23] (Realtek )
S0 Avgboota; C:\Windows\System32\DRIVERS\avgboota.sys [23152 2015-09-09] (AVG Technologies CZ, s.r.o.)
R1 Avgdiska; C:\Windows\System32\DRIVERS\avgdiska.sys [184240 2015-11-06] (AVG Technologies CZ, s.r.o.)
R1 AVGIDSDriver; C:\Windows\System32\DRIVERS\avgidsdrivera.sys [313776 2015-11-06] (AVG Technologies CZ, s.r.o.)
R0 AVGIDSHA; C:\Windows\System32\DRIVERS\avgidsha.sys [298416 2015-08-20] (AVG Technologies CZ, s.r.o.)
R1 Avgldx64; C:\Windows\System32\DRIVERS\avgldx64.sys [284080 2015-10-21] (AVG Technologies CZ, s.r.o.)
R0 Avgloga; C:\Windows\System32\DRIVERS\avgloga.sys [398256 2015-08-14] (AVG Technologies CZ, s.r.o.)
R0 Avgmfx64; C:\Windows\System32\DRIVERS\avgmfx64.sys [256432 2015-11-06] (AVG Technologies CZ, s.r.o.)
R0 Avgrkx64; C:\Windows\System32\DRIVERS\avgrkx64.sys [42416 2015-08-10] (AVG Technologies CZ, s.r.o.)
R1 Avgwfpa; C:\Windows\system32\DRIVERS\avgwfpa.sys [306608 2015-10-08] (AVG Technologies CZ, s.r.o.)
S3 cpuz138; C:\Users\ERIK\AppData\Local\Temp\cpuz138\cpuz138_x64.sys [27320 2015-10-14] (CPUID)
R1 dtsoftbus01; C:\Windows\System32\drivers\dtsoftbus01.sys [283064 2014-05-29] (Disc Soft Ltd)
S0 ebdrv; C:\Windows\System32\drivers\evbda.sys [3265256 2012-09-20] (Broadcom Corporation)
R3 Hamachi; C:\Windows\system32\DRIVERS\Hamdrv.sys [45680 2015-11-12] (LogMeIn Inc.)
R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25816 2014-05-12] (Malwarebytes Corporation)
S3 MBAMSwissArmy; C:\Windows\system32\drivers\MBAMSwissArmy.sys [122584 2014-09-28] (Malwarebytes Corporation)
S3 MBAMWebAccessControl; C:\Windows\system32\drivers\mwac.sys [64216 2014-05-12] (Malwarebytes Corporation)
S0 prohlp01; C:\Windows\SysWOW64\drivers\prohlp01.sys [75936 2002-10-05] (Protection Technology Co.) [File not signed]
S0 prohlp02; C:\Windows\SysWOW64\drivers\prohlp02.sys [94464 2003-04-28] (StarForce Technologies, Inc.) [File not signed]
S0 prosync1; C:\Windows\SysWOW64\drivers\prosync1.sys [6848 2003-04-04] (StarForce Technologies, Inc.) [File not signed]
R3 SensorsSimulatorDriver; C:\Windows\system32\DRIVERS\WUDFRd.sys [198656 2012-07-26] (Microsoft Corporation)
S0 sfhlp01; C:\Windows\SysWOW64\drivers\sfhlp01.sys [4448 2003-04-29] (StarForce Technologies, Inc.) [File not signed]
S3 ssudserd; C:\Windows\system32\DRIVERS\ssudserd.sys [206080 2014-01-22] (DEVGURU Co., LTD.(
www.devguru.co.kr))
R3 tap0901t; C:\Windows\system32\DRIVERS\tap0901t.sys [31232 2009-09-16] (Tunngle.net)
R3 TuneUpUtilitiesDrv; C:\Program Files (x86)\TuneUp Utilities 2014\TuneUpUtilitiesDriver64.sys [14112 2013-08-21] (TuneUp Software)
S3 V0700Vid; C:\Windows\system32\DRIVERS\V0700Vid.sys [393920 2011-09-06] (Creative Technology Ltd.)
S3 WdBoot; C:\Windows\system32\drivers\WdBoot.sys [44560 2015-07-06] (Microsoft Corporation)
S3 WdFilter; C:\Windows\system32\drivers\WdFilter.sys [281944 2015-07-06] (Microsoft Corporation)
S2 BstHdDrv; \??\C:\Program Files (x86)\BlueStacks\HD-Hypervisor-amd64.sys [X]
S3 catchme; \??\C:\ComboFix\catchme.sys [X]
S1 prodrv05; \SystemRoot\System32\drivers\prodrv05.sys [X]
S1 prodrv06; \SystemRoot\System32\drivers\prodrv06.sys [X]
S3 xhunter1; \??\C:\Windows\xhunter1.sys [X]
S1 {f9d2f209-1697-4837-85f2-d88e4c9f7c81}Gw64; system32\drivers\{f9d2f209-1697-4837-85f2-d88e4c9f7c81}Gw64.sys [X]
==================== NetSvcs (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
==================== One Month Created files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2016-01-05 16:26 - 2016-01-05 16:27 - 00295880 _____ C:\Windows\Minidump\010516-58250-01.dmp
2016-01-05 16:26 - 2016-01-05 16:26 - 529413932 _____ C:\Windows\MEMORY.DMP
2016-01-05 15:14 - 2016-01-05 15:14 - 00295328 _____ C:\Windows\Minidump\010516-55015-01.dmp
2016-01-04 20:17 - 2016-01-04 20:17 - 00296184 _____ C:\Windows\Minidump\010416-56265-01.dmp
2016-01-04 17:58 - 2016-01-04 17:59 - 00295144 _____ C:\Windows\Minidump\010416-53609-01.dmp
2016-01-03 00:00 - 2016-01-03 00:00 - 00293976 _____ C:\Windows\Minidump\010316-52046-01.dmp
2016-01-02 23:06 - 2016-01-02 23:06 - 00297344 _____ C:\Windows\Minidump\010216-53484-01.dmp
2016-01-02 22:17 - 2016-01-02 22:17 - 00295032 _____ C:\Windows\Minidump\010216-52250-01.dmp
2016-01-02 21:39 - 2016-01-02 21:39 - 00297680 _____ C:\Windows\Minidump\010216-51750-01.dmp
2016-01-02 18:15 - 2016-01-02 18:15 - 00000825 _____ C:\Users\ERIK\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Start Tor Browser.lnk
2016-01-02 18:15 - 2016-01-02 18:15 - 00000777 _____ C:\Users\ERIK\Desktop\Start Tor Browser.lnk
2016-01-02 18:11 - 2016-01-02 18:11 - 00000000 ____D C:\Users\ERIK\Desktop\Tor Browser
2016-01-02 18:08 - 2016-01-02 18:09 - 44218904 _____ C:\Users\ERIK\Downloads\torbrowser-install-5.0.6_en-US.exe
2016-01-02 13:46 - 2016-01-02 13:46 - 00296376 _____ C:\Windows\Minidump\010216-59437-01.dmp
2016-01-02 13:03 - 2016-01-03 16:36 - 00000000 ____D C:\AdwCleaner
2016-01-02 13:03 - 2016-01-02 13:02 - 01745920 _____ C:\Users\ERIK\Desktop\adwcleaner_5.027.exe
2016-01-02 13:02 - 2016-01-02 13:02 - 01745920 _____ C:\Users\ERIK\Downloads\adwcleaner_5.027.exe
2016-01-02 12:58 - 2016-01-02 12:58 - 00297640 _____ C:\Windows\Minidump\010216-52406-01.dmp
2016-01-02 11:55 - 2016-01-04 21:20 - 00120146 _____ C:\Users\ERIK\Desktop\Addition.txt
2016-01-02 11:54 - 2016-01-05 16:38 - 00032656 _____ C:\Users\ERIK\Desktop\FRST.txt
2016-01-02 11:54 - 2016-01-05 16:38 - 00000000 ____D C:\FRST
2016-01-02 11:53 - 2016-01-02 11:53 - 02370560 _____ (Farbar) C:\Users\ERIK\Downloads\FRST64.exe
2016-01-02 11:53 - 2016-01-02 11:53 - 02370560 _____ (Farbar) C:\Users\ERIK\Desktop\FRST64.exe
2015-12-29 18:29 - 2015-12-29 18:30 - 00297512 _____ C:\Windows\Minidump\122915-127015-01.dmp
2015-12-29 14:41 - 2015-12-29 14:41 - 00296192 _____ C:\Windows\Minidump\122915-58343-01.dmp
2015-12-28 12:20 - 2015-12-28 12:20 - 00297672 _____ C:\Windows\Minidump\122815-130718-01.dmp
2015-12-28 09:49 - 2015-12-28 09:49 - 00000000 ____D C:\Users\ERIK\AppData\Local\master131
2015-12-28 09:43 - 2015-12-28 09:43 - 00000000 ____D C:\Users\ERIK\Documents\MEGAsync Downloads
2015-12-28 09:42 - 2015-12-28 09:42 - 01166288 _____ C:\Users\ERIK\Downloads\Blockade 3D HACK by Vednix.rar
2015-12-28 09:40 - 2015-12-28 09:40 - 10152576 _____ (MEGA Limited) C:\Users\ERIK\Downloads\MEGAsyncSetup (1).exe
2015-12-28 09:40 - 2015-12-28 09:40 - 00260774 _____ C:\Users\ERIK\Downloads\BLOCKADE 3D HACK.rar
2015-12-27 18:52 - 2015-12-27 18:53 - 00297664 _____ C:\Windows\Minidump\122715-71625-01.dmp
2015-12-27 16:33 - 2015-12-27 16:33 - 04239055 _____ C:\Users\ERIK\Downloads\stobyv_20151109.zip
2015-12-27 14:30 - 2015-12-27 14:31 - 00297632 _____ C:\Windows\Minidump\122715-64562-01.dmp
2015-12-26 20:20 - 2015-12-26 20:20 - 00000202 _____ C:\Users\ERIK\Desktop\BLOCKADE 3D.url
2015-12-26 19:09 - 2015-12-26 19:22 - 00000000 ____D C:\Users\ERIK\AppData\Local\AVG Web TuneUp
2015-12-26 19:09 - 2015-12-26 19:09 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox
2015-12-26 19:08 - 2015-12-26 19:09 - 00000000 ____D C:\ProgramData\AVG Web TuneUp
2015-12-26 19:08 - 2015-12-26 19:08 - 00000000 ____D C:\Program Files (x86)\AVG Web TuneUp
2015-12-25 02:25 - 2015-12-25 02:25 - 00296864 _____ C:\Windows\Minidump\122515-87953-01.dmp
2015-12-24 19:34 - 2015-12-24 19:39 - 446309491 _____ C:\Users\ERIK\Downloads\Grand.Theft.Auto.V.Update.5(v1.0.350.2).and.Crack.v4-3DM.zip
2015-12-24 14:07 - 2015-12-26 15:42 - 00000080 _____ C:\Users\ERIK\AppData\Local剜捯獫慴慇敭屳呇⁁屖湥楴汴浥湥湩潦
2015-12-24 14:07 - 2015-12-24 14:07 - 00000000 ____D C:\Users\ERIK\Documents\Rockstar Games
2015-12-24 14:07 - 2015-12-24 14:07 - 00000000 ____D C:\Users\ERIK\AppData\Local\Rockstar Games
2015-12-24 13:14 - 2015-12-24 13:14 - 00000000 ____D C:\Program Files (x86)\Rockstar Games
2015-12-24 13:13 - 2015-12-24 13:13 - 00000000 ____D C:\Program Files\Rockstar Games
2015-12-24 12:05 - 2015-12-24 12:05 - 00000517 _____ C:\Users\Public\Desktop\Grand Theft Auto V.lnk
2015-12-24 12:05 - 2015-12-24 12:05 - 00000517 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Grand Theft Auto V.lnk
2015-12-23 15:49 - 2015-12-23 15:49 - 00003498 _____ C:\Windows\System32\Tasks\AdobeAAMUpdater-1.0-DOMA225-ERIK
2015-12-23 15:29 - 2015-12-23 15:29 - 00001000 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Photoshop CC 2015.lnk
2015-12-23 15:29 - 2015-12-23 15:29 - 00000000 ____D C:\Users\ERIK\Documents\Adobe
2015-12-23 15:24 - 2015-12-23 15:24 - 00393725 _____ C:\Users\ERIK\Downloads\slevomat-cz-voucher-relax-v-mariankach-polopenze-i-wellness-5980652210A-580 (2).pdf
2015-12-23 15:24 - 2015-12-23 15:24 - 00196023 _____ C:\Users\ERIK\Downloads\slevomat-cz-voucher-relax-v-mariankach-polopenze-i-wellness-5980652210A-580 (1).pdf
2015-12-23 15:23 - 2015-12-23 15:23 - 00393725 _____ C:\Users\ERIK\Downloads\slevomat-cz-voucher-relax-v-mariankach-polopenze-i-wellness-5980652210A-580.pdf
2015-12-23 15:20 - 2015-12-23 15:33 - 00000000 ____D C:\Program Files\Adobe
2015-12-23 15:05 - 2015-12-23 15:05 - 00000000 ___RD C:\Users\ERIK\Creative Cloud Files
2015-12-23 15:05 - 2015-12-23 15:05 - 00000000 ____D C:\ProgramData\boost_interprocess
2015-12-23 14:36 - 2015-12-23 14:36 - 00001213 _____ C:\Users\Public\Desktop\Adobe Creative Cloud.lnk
2015-12-23 14:33 - 2015-12-23 14:33 - 00689344 _____ (Adobe Systems Incorporated) C:\Users\ERIK\Downloads\CreativeCloudSet-Up.exe
2015-12-23 01:47 - 2015-12-23 01:47 - 00303101 _____ C:\Users\ERIK\Downloads\GTA 5 - Grand Theft Auto V-RELOADED-.torrent
2015-12-23 01:26 - 2015-12-23 01:27 - 00297232 _____ C:\Windows\Minidump\122315-53609-01.dmp
2015-12-22 15:21 - 2015-12-22 15:21 - 00305840 _____ C:\Windows\Minidump\122215-56953-01.dmp
2015-12-21 17:43 - 2015-12-21 17:43 - 00855887 _____ C:\Users\ERIK\Downloads\Filter_Extensions-2.4.1.3.zip
2015-12-20 19:00 - 2015-12-20 19:31 - 665506608 _____ C:\Users\ERIK\Downloads\Universe Sandbox 2 Captain Pirate.zip
2015-12-20 18:29 - 2015-12-20 18:29 - 00000681 _____ C:\Users\ERIK\Desktop\Kerbal Space Program.lnk
2015-12-20 18:29 - 2015-12-20 18:29 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Kerbal Space Program
2015-12-20 18:18 - 2015-12-20 18:18 - 00015314 _____ C:\Users\ERIK\Downloads\Kerbal.space.program.codex.torrent
2015-12-20 16:41 - 2015-12-20 16:41 - 00297640 _____ C:\Windows\Minidump\122015-60046-01.dmp
2015-12-20 15:55 - 2015-12-20 15:55 - 00000165 ____H C:\Users\ERIK\Downloads\~$Vánoce jsou tady!.pptx
2015-12-20 14:51 - 2015-12-20 16:09 - 01023341 _____ C:\Users\ERIK\Downloads\Vánoce jsou tady!.pptx
2015-12-19 17:57 - 2015-12-19 17:57 - 00297304 _____ C:\Windows\Minidump\121915-43984-01.dmp
2015-12-19 11:15 - 2015-12-19 11:15 - 00297696 _____ C:\Windows\Minidump\121915-229140-01.dmp
2015-12-15 17:54 - 2015-12-15 17:54 - 02501120 _____ C:\Users\ERIK\Downloads\Kostra (1).pps
2015-12-15 17:53 - 2015-12-15 17:53 - 02498560 _____ C:\Users\ERIK\Downloads\Kostra.pps
2015-12-15 17:50 - 2015-12-15 17:50 - 02904064 _____ C:\Users\ERIK\Downloads\ochrany.pps
2015-12-15 17:16 - 2015-12-15 17:16 - 02796544 _____ C:\Users\ERIK\Downloads\8.-Pohybová-soustava.ppt
2015-12-15 16:26 - 2015-12-15 16:26 - 00295656 _____ C:\Windows\Minidump\121515-65171-01.dmp
2015-12-14 22:02 - 2015-12-14 22:03 - 00297696 _____ C:\Windows\Minidump\121415-56593-01.dmp
2015-12-14 20:07 - 2015-12-14 20:07 - 00297672 _____ C:\Windows\Minidump\121415-70125-01.dmp
2015-12-12 16:37 - 2015-12-12 16:38 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Skype
2015-12-12 16:32 - 2015-12-12 16:32 - 00297632 _____ C:\Windows\Minidump\121215-54281-01.dmp
2015-12-10 20:33 - 2015-12-10 20:34 - 00297704 _____ C:\Windows\Minidump\121015-76937-01.dmp
2015-12-09 19:36 - 2015-12-09 19:37 - 05090552 _____ C:\Windows\system32\FNTCACHE.DAT
2015-12-09 13:36 - 2015-12-09 13:36 - 00297656 _____ C:\Windows\Minidump\120915-51718-01.dmp
2015-12-08 19:16 - 2015-12-08 19:16 - 00297464 _____ C:\Windows\Minidump\120815-49640-01.dmp
2015-12-08 17:34 - 2015-12-08 17:35 - 00297696 _____ C:\Windows\Minidump\120815-321140-01.dmp
2015-12-08 16:30 - 2015-11-16 17:17 - 06970712 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe
2015-12-08 16:30 - 2015-11-16 17:10 - 01821192 _____ (Microsoft Corporation) C:\Windows\system32\ntdll.dll
2015-12-08 16:30 - 2015-11-16 15:55 - 01410000 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntdll.dll
2015-12-08 16:30 - 2015-11-16 15:42 - 00171864 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecpkg.sys
2015-12-08 16:30 - 2015-11-16 15:29 - 00961536 _____ (Microsoft Corporation) C:\Windows\SysWOW64\usercpl.dll
2015-12-08 16:30 - 2015-11-16 15:29 - 00452608 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SHCore.dll
2015-12-08 16:30 - 2015-11-16 15:29 - 00273920 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msv1_0.dll
2015-12-08 16:30 - 2015-11-16 15:29 - 00178688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wdigest.dll
2015-12-08 16:30 - 2015-11-16 15:29 - 00076800 _____ (Microsoft Corporation) C:\Windows\SysWOW64\TSpkg.dll
2015-12-08 16:30 - 2015-11-16 15:28 - 01223168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\comsvcs.dll
2015-12-08 16:30 - 2015-11-16 15:28 - 00668160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kerberos.dll
2015-12-08 16:30 - 2015-11-16 15:28 - 00384512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\catsrvut.dll
2015-12-08 16:30 - 2015-11-16 15:28 - 00017408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\credssp.dll
2015-12-08 16:30 - 2015-11-16 15:27 - 00578048 _____ (Microsoft Corporation) C:\Windows\system32\winlogon.exe
2015-12-08 16:30 - 2015-11-16 15:26 - 01637376 _____ (Microsoft Corporation) C:\Windows\system32\comsvcs.dll
2015-12-08 16:30 - 2015-11-16 15:26 - 01282560 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll
2015-12-08 16:30 - 2015-11-16 15:26 - 01043968 _____ (Microsoft Corporation) C:\Windows\system32\usercpl.dll
2015-12-08 16:30 - 2015-11-16 15:26 - 00830464 _____ (Microsoft Corporation) C:\Windows\system32\kerberos.dll
2015-12-08 16:30 - 2015-11-16 15:26 - 00588800 _____ (Microsoft Corporation) C:\Windows\system32\SHCore.dll
2015-12-08 16:30 - 2015-11-16 15:26 - 00499200 _____ (Microsoft Corporation) C:\Windows\system32\catsrvut.dll
2015-12-08 16:30 - 2015-11-16 15:26 - 00439808 _____ (Microsoft Corporation) C:\Windows\system32\lsm.dll
2015-12-08 16:30 - 2015-11-16 15:26 - 00318464 _____ (Microsoft Corporation) C:\Windows\system32\msv1_0.dll
2015-12-08 16:30 - 2015-11-16 15:26 - 00208896 _____ (Microsoft Corporation) C:\Windows\system32\wdigest.dll
2015-12-08 16:30 - 2015-11-16 15:26 - 00164864 _____ (Microsoft Corporation) C:\Windows\system32\sspicli.dll
2015-12-08 16:30 - 2015-11-16 15:26 - 00094720 _____ (Microsoft Corporation) C:\Windows\system32\TSpkg.dll
2015-12-08 16:30 - 2015-11-16 15:26 - 00020480 _____ (Microsoft Corporation) C:\Windows\system32\credssp.dll
2015-12-08 16:29 - 2015-11-07 13:46 - 02238976 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2015-12-08 16:29 - 2015-11-07 13:46 - 01408512 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2015-12-08 16:29 - 2015-11-07 13:46 - 01341952 _____ (Microsoft Corporation) C:\Windows\system32\user32.dll
2015-12-08 16:29 - 2015-11-07 13:46 - 00915968 _____ (Microsoft Corporation) C:\Windows\system32\uxtheme.dll
2015-12-08 16:29 - 2015-11-07 13:46 - 00592384 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2015-12-08 16:29 - 2015-11-07 13:46 - 00053760 _____ (Microsoft Corporation) C:\Windows\system32\UXInit.dll
2015-12-08 16:29 - 2015-11-07 13:45 - 19349504 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2015-12-08 16:29 - 2015-11-07 13:45 - 00603136 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2015-12-08 16:29 - 2015-11-07 13:45 - 00097280 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2015-12-08 16:29 - 2015-11-07 13:44 - 15423488 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2015-12-08 16:29 - 2015-11-07 13:44 - 03806208 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2015-12-08 16:29 - 2015-11-07 13:44 - 02657280 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2015-12-08 16:29 - 2015-11-07 13:44 - 01840640 _____ (Microsoft Corporation) C:\Windows\system32\DWrite.dll
2015-12-08 16:29 - 2015-11-07 13:44 - 01509376 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2015-12-08 16:29 - 2015-11-07 13:44 - 01280000 _____ (Microsoft Corporation) C:\Windows\system32\FntCache.dll
2015-12-08 16:29 - 2015-11-07 13:44 - 00949760 _____ (Microsoft Corporation) C:\Windows\system32\inetcomm.dll
2015-12-08 16:29 - 2015-11-07 13:44 - 00857600 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
2015-12-08 16:29 - 2015-11-07 13:44 - 00281600 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2015-12-08 16:29 - 2015-11-07 13:44 - 00255488 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll
2015-12-08 16:29 - 2015-11-07 10:34 - 01763328 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2015-12-08 16:29 - 2015-11-07 10:34 - 01181696 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2015-12-08 16:29 - 2015-11-07 10:34 - 00513536 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll
2015-12-08 16:29 - 2015-11-07 10:34 - 00044032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\UXInit.dll
2015-12-08 16:29 - 2015-11-07 10:33 - 14269440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2015-12-08 16:29 - 2015-11-07 10:33 - 13723136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2015-12-08 16:29 - 2015-11-07 10:33 - 02793984 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2015-12-08 16:29 - 2015-11-07 10:33 - 02057216 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2015-12-08 16:29 - 2015-11-07 10:33 - 00737280 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcomm.dll
2015-12-08 16:29 - 2015-11-07 10:33 - 00715776 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2015-12-08 16:29 - 2015-11-07 10:33 - 00493056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2015-12-08 16:29 - 2015-11-07 10:33 - 00226816 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll
2015-12-08 16:29 - 2015-11-07 10:33 - 00226816 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll
2015-12-08 16:29 - 2015-11-07 10:33 - 00080384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2015-12-08 16:29 - 2015-11-07 10:32 - 01412608 _____ (Microsoft Corporation) C:\Windows\SysWOW64\DWrite.dll
2015-12-08 16:29 - 2015-11-07 08:52 - 04063232 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2015-12-08 16:29 - 2015-11-07 06:53 - 01126912 _____ (Microsoft Corporation) C:\Windows\SysWOW64\user32.dll
2015-12-08 16:29 - 2015-11-07 06:52 - 01680384 _____ (Microsoft Corporation) C:\Windows\system32\GdiPlus.dll
2015-12-08 16:29 - 2015-11-07 06:46 - 01426944 _____ (Microsoft Corporation) C:\Windows\SysWOW64\GdiPlus.dll
2015-12-08 16:29 - 2015-11-07 06:29 - 00534528 _____ (Microsoft Corporation) C:\Windows\SysWOW64\uxtheme.dll
2015-12-08 16:29 - 2015-11-05 10:55 - 00147968 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\rmcast.sys
2015-12-08 16:29 - 2015-10-31 09:14 - 02038784 _____ (Microsoft Corporation) C:\Windows\SysWOW64\authui.dll
2015-12-08 16:29 - 2015-10-31 08:33 - 02308096 _____ (Microsoft Corporation) C:\Windows\system32\authui.dll
2015-12-08 16:29 - 2015-10-24 06:28 - 00601088 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Globalization.dll
2015-12-08 16:29 - 2015-10-24 06:24 - 00951808 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Globalization.dll
2015-12-08 16:29 - 2015-10-22 20:01 - 00007168 _____ (Microsoft Corporation) C:\Windows\system32\kbdgeoqw.dll
2015-12-08 16:29 - 2015-10-22 20:01 - 00007168 _____ (Microsoft Corporation) C:\Windows\system32\KBDAZEL.DLL
2015-12-08 16:29 - 2015-10-22 20:01 - 00007168 _____ (Microsoft Corporation) C:\Windows\system32\KBDAZE.DLL
2015-12-08 16:29 - 2015-10-22 20:01 - 00006656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kbdgeoqw.dll
2015-12-08 16:29 - 2015-10-22 20:00 - 00007168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KBDAZE.DLL
2015-12-08 16:29 - 2015-10-22 20:00 - 00006656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KBDAZEL.DLL
2015-12-08 16:29 - 2015-10-22 14:43 - 00478280 _____ C:\Windows\SysWOW64\locale.nls
2015-12-08 16:29 - 2015-10-22 14:42 - 00478280 _____ C:\Windows\system32\locale.nls
2015-12-08 16:11 - 2015-12-08 16:12 - 00297648 _____ C:\Windows\Minidump\120815-62171-01.dmp
2015-12-07 15:42 - 2015-12-07 20:11 - 00551934 _____ C:\Users\ERIK\Downloads\Linka bezpečí.pptx
2015-12-06 19:53 - 2015-12-06 19:53 - 00000000 ____D C:\Users\ERIK\AppData\LocalLow\Unknown Worlds
2015-12-06 16:01 - 2015-12-06 17:12 - 1789904563 _____ C:\Users\ERIK\Downloads\Subnautica.Build.v990.rar
2015-12-06 15:58 - 2015-12-06 15:58 - 00040419 _____ C:\Users\ERIK\Downloads\download_repair (1).htm
2015-12-06 15:56 - 2015-12-06 15:56 - 00040419 _____ C:\Users\ERIK\Downloads\download_repair.htm
==================== One Month Modified files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2016-01-05 16:36 - 2015-07-07 16:28 - 00000000 ____D C:\Users\ERIK\AppData\Local\LogMeIn Hamachi
2016-01-05 16:35 - 2015-10-14 21:05 - 00000972 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2016-01-05 16:35 - 2015-05-04 16:50 - 00065536 _____ C:\Windows\system32\Ikeext.etl
2016-01-05 16:35 - 2013-12-10 22:20 - 00000000 ____D C:\ProgramData\NVIDIA
2016-01-05 16:35 - 2012-07-26 08:22 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2016-01-05 16:32 - 2012-07-26 09:12 - 00000000 ____D C:\Windows\tracing
2016-01-05 16:26 - 2014-02-02 20:25 - 00000000 ____D C:\Windows\Minidump
2016-01-05 16:26 - 2012-07-26 06:37 - 00000000 ____D C:\Windows
2016-01-05 15:34 - 2015-11-07 14:58 - 00000830 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job
2016-01-05 15:19 - 2014-08-08 18:05 - 00000000 ____D C:\Users\ERIK\AppData\Local\Adobe
2016-01-05 15:18 - 2014-10-10 18:16 - 00000000 ____D C:\ProgramData\MFAData
2016-01-05 15:15 - 2015-10-14 21:05 - 00000976 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2016-01-05 15:15 - 2015-10-14 15:26 - 00003600 _____ C:\Windows\System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-2796967165-1696306274-2783790974-1001
2016-01-04 17:45 - 2012-07-26 06:26 - 00262144 ___SH C:\Windows\system32\config\BBI
2016-01-03 16:19 - 2014-04-14 20:03 - 03308032 ___SH C:\Users\ERIK\Downloads\Thumbs.db
2016-01-02 23:44 - 2015-11-14 11:55 - 00000892 _____ C:\Windows\Tasks\Adobe Flash Player PPAPI Notifier.job
2016-01-02 18:38 - 2012-07-26 06:37 - 00000000 ____D C:\Windows\Inf
2016-01-02 16:35 - 2013-12-11 18:40 - 00000000 ____D C:\Users\ERIK\AppData\Roaming\Skype
2016-01-02 09:50 - 2012-07-26 06:26 - 00262144 ___SH C:\Windows\system32\config\ELAM
2015-12-30 10:54 - 2015-02-19 13:16 - 00000000 ____D C:\Users\ERIK\AppData\Local\Steam
2015-12-29 14:28 - 2012-07-26 08:59 - 00000000 ____D C:\Windows\CbsTemp
2015-12-29 13:42 - 2012-07-26 08:28 - 00898288 _____ C:\Windows\system32\PerfStringBackup.INI
2015-12-28 19:34 - 2015-11-14 11:55 - 00003852 _____ C:\Windows\System32\Tasks\Adobe Flash Player PPAPI Notifier
2015-12-28 19:34 - 2015-11-07 14:58 - 00003718 _____ C:\Windows\System32\Tasks\Adobe Flash Player Updater
2015-12-28 09:40 - 2015-11-01 14:13 - 00001052 _____ C:\Users\ERIK\Desktop\MEGAsync.lnk
2015-12-28 09:40 - 2015-11-01 14:13 - 00000000 ____D C:\Users\ERIK\AppData\Local\MEGAsync
2015-12-26 20:20 - 2015-06-04 15:53 - 00000000 ____D C:\Users\ERIK\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Steam
2015-12-26 19:22 - 2014-03-09 12:47 - 00083968 ___SH C:\Users\ERIK\Desktop\Thumbs.db
2015-12-26 15:58 - 2014-06-04 17:30 - 00000000 ____D C:\Users\ERIK\AppData\Local\ElevatedDiagnostics
2015-12-26 15:58 - 2012-07-26 09:12 - 00000000 ____D C:\Windows\system32\NDF
2015-12-26 09:54 - 2014-10-19 09:57 - 00826328 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2015-12-26 09:54 - 2014-10-19 09:57 - 00176096 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2015-12-25 02:40 - 2013-12-10 21:57 - 00000000 ____D C:\Users\ERIK
2015-12-24 21:15 - 2015-05-06 20:28 - 00000000 ____D C:\Users\ERIK\Desktop\zp
2015-12-23 15:49 - 2014-05-08 18:37 - 00000000 ____D C:\ProgramData\regid.1986-12.com.adobe
2015-12-23 15:49 - 2013-12-10 21:58 - 00000000 ____D C:\Users\ERIK\AppData\Roaming\Adobe
2015-12-23 15:46 - 2014-04-13 14:49 - 00000000 ____D C:\Program Files\Common Files\Adobe
2015-12-23 15:40 - 2013-12-11 08:29 - 00000000 ____D C:\Program Files (x86)\Adobe
2015-12-23 15:24 - 2014-04-13 14:29 - 00000000 ____D C:\ProgramData\Package Cache
2015-12-23 15:18 - 2013-12-11 08:29 - 00000000 ____D C:\ProgramData\Adobe
2015-12-23 14:36 - 2014-04-13 14:29 - 00001225 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Creative Cloud.lnk
2015-12-12 16:38 - 2013-12-11 08:29 - 00000000 ____D C:\ProgramData\Skype
2015-12-12 16:37 - 2014-11-26 17:59 - 00000000 ___RD C:\Program Files (x86)\Skype
2015-12-12 16:37 - 2014-11-26 17:59 - 00000000 ____D C:\Users\ERIK\AppData\Local\Skype
2015-12-10 17:29 - 2015-07-21 20:01 - 00000000 ____D C:\Windows\rescache
2015-12-09 17:25 - 2014-05-09 17:47 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Silverlight
2015-12-09 17:25 - 2013-12-11 08:20 - 00000000 ____D C:\ProgramData\Microsoft Help
2015-12-09 17:24 - 2014-05-09 17:46 - 00000000 ____D C:\Program Files\Microsoft Silverlight
2015-12-09 17:24 - 2014-05-09 17:46 - 00000000 ____D C:\Program Files (x86)\Microsoft Silverlight
2015-12-09 15:42 - 2012-07-26 09:12 - 00000000 ___RD C:\Windows\ToastData
2015-12-09 15:25 - 2013-12-10 22:34 - 140158008 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2015-12-09 15:25 - 2013-12-10 22:34 - 00000000 ____D C:\Windows\system32\MRT
2015-12-08 19:19 - 2014-06-01 16:34 - 00000000 ____D C:\ProgramData\Origin
2015-12-08 17:37 - 2013-12-10 22:20 - 00000000 ____D C:\Users\UpdatusUser
==================== Files in the root of some directories =======
2014-05-31 13:17 - 2014-05-31 13:17 - 0000000 _____ () C:\Users\ERIK\AppData\Roaming\bitlord_log.txt
2014-10-10 18:45 - 2014-10-10 18:45 - 0000000 ___SH () C:\Users\ERIK\AppData\Local\LumaEmu
2015-09-30 17:14 - 2015-09-30 17:14 - 0000000 _____ () C:\Users\ERIK\AppData\Local\{EDA499EE-C7CD-4DE3-AC2E-463886C17FD1}
2013-12-10 22:43 - 2013-12-10 22:43 - 0000000 ____H () C:\ProgramData\DP45977C.lfl
Some files in TEMP:
====================
C:\Users\ERIK\AppData\Local\temp\04ee6e45397ed3b92101a8fdb2f38ef0.dll
C:\Users\ERIK\AppData\Local\temp\0e083b80b7f146f2f4538c2c7696d104.dll
C:\Users\ERIK\AppData\Local\temp\AcDeltree.exe
C:\Users\ERIK\AppData\Local\temp\avg-e5372161-1274-4846-93f9-c25500358a11.exe
C:\Users\ERIK\AppData\Local\temp\drm_dyndata_7380015.dll
C:\Users\ERIK\AppData\Local\temp\eauninstall.exe
C:\Users\ERIK\AppData\Local\temp\ed6e8e8c4b588010c8f64663407c6196.dll
C:\Users\ERIK\AppData\Local\temp\i4jdel0.exe
C:\Users\ERIK\AppData\Local\temp\InstHelper.exe
C:\Users\ERIK\AppData\Local\temp\mediaget-uninstaller.exe
C:\Users\ERIK\AppData\Local\temp\SimCity 4 Deluxe_uninst.exe
C:\Users\ERIK\AppData\Local\temp\sonarinst.exe
C:\Users\ERIK\AppData\Local\temp\sqlite-3.8.2-x86-sqlitejdbc.dll
C:\Users\ERIK\AppData\Local\temp\sqlite3.dll
C:\Users\ERIK\AppData\Local\temp\yupdate-exec-yabrowser.exe
C:\Users\ERIK\AppData\Local\temp\{D73C17D4-6C8E-487F-9142-F10B90512CFF}.exe
C:\Users\ERIK\AppData\Local\temp\{F747C784-57B1-4020-80D4-A9DCE1634ABC}-GoogleUpdateSetup.exe
==================== Bamital & volsnap =================
(There is no automatic fix for files that do not pass verification.)
C:\Windows\system32\winlogon.exe => File is digitally signed
C:\Windows\system32\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\system32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\system32\services.exe => File is digitally signed
C:\Windows\system32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\system32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\system32\rpcss.dll => File is digitally signed
C:\Windows\system32\dnsapi.dll => File is digitally signed
C:\Windows\SysWOW64\dnsapi.dll => File is digitally signed
C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed
LastRegBack: 2015-12-29 12:03
==================== End of FRST.txt ============================