prosím kontrolu
Napsal: 02 led 2016 22:46
Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version:31-12-2015
Ran by honza (administrator) on MARTIN (02-01-2016 21:53:21)
Running from C:\Users\honza\Desktop
Loaded Profiles: honza (Available Profiles: honza & Guest)
Platform: Windows 7 Home Premium (X64) Language: Čeština (Česká republika)
Internet Explorer Version 9 (Default browser: Chrome)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/33 ... scan-tool/
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(AMD) C:\Windows\System32\atiesrxx.exe
(AMD) C:\Windows\System32\atieclxx.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe
(SUPERAntiSpyware.com) C:\Program Files\SUPERAntiSpyware\SASCore64.exe
(Broadcom Corporation.) C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe
(Comodo) C:\Program Files (x86)\Comodo\Dragon\dragon_updater.exe
(Macrovision Corporation) C:\Program Files (x86)\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
(Google Inc.) C:\Program Files (x86)\Google\Update\1.3.29.1\GoogleCrashHandler.exe
(Google Inc.) C:\Program Files (x86)\Google\Update\1.3.29.1\GoogleCrashHandler64.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(ArcSoft, Inc.) C:\Program Files (x86)\ArcSoft\Magic-i Visual Effects 2\uCamMonitor.exe
(Sony Corporation) C:\Program Files\Sony\VAIO Power Management\SPMgr.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastUI.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
==================== Registry (Whitelisted) ===========================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM-x32\...\Run: [AvastUI.exe] => C:\Program Files\AVAST Software\Avast\AvastUI.exe [7021880 2015-12-06] (AVAST Software)
Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation)
HKU\S-1-5-21-866132977-3524765048-2583430549-1000\...\RunOnce: [FlashPlayerUpdate] => C:\Windows\SysWOW64\Macromed\Flash\FlashUtil32_19_0_0_245_pepper.exe [1158856 2015-12-02] (Adobe Systems Incorporated)
HKU\S-1-5-21-866132977-3524765048-2583430549-1000\...\MountPoints2: {e162d644-151a-11e5-b93d-ec55f9e929bb} - E:\setup.exe
HKU\S-1-5-21-866132977-3524765048-2583430549-1000\...\MountPoints2: {e162d647-151a-11e5-b93d-ec55f9e929bb} - G:\m.exe
HKU\S-1-5-21-866132977-3524765048-2583430549-1000\...\MountPoints2: {e17b9178-a0e5-11e4-a51d-ec55f9e929bb} - J:\HiSuiteDownLoader.exe
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - %SystemRoot%\system32\wpdshserviceobj.dll (Microsoft Corporation)
ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShA64.dll [2015-12-06] (AVAST Software)
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
Tcpip\Parameters: [DhcpNameServer] 192.168.43.1
Tcpip\..\Interfaces\{25559BA7-6EF9-45A1-8A74-5DE0661ACE12}: [DhcpNameServer] 192.168.42.129
Tcpip\..\Interfaces\{A3BBF46B-A159-4BF4-B070-5D52FC44EA02}: [DhcpNameServer] 10.0.0.138
Tcpip\..\Interfaces\{A54718C9-FD98-4D35-9BC5-17E8F314811B}: [DhcpNameServer] 192.168.100.254
Tcpip\..\Interfaces\{D814BF20-A917-41A7-BDAA-43E59F9CD8E7}: [DhcpNameServer] 192.168.42.129
Tcpip\..\Interfaces\{FCCB9CFF-7B76-46F5-A504-F6C1EE5BE0D5}: [DhcpNameServer] 192.168.43.1
Internet Explorer:
==================
HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Local Page =
SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-21-866132977-3524765048-2583430549-1000 -> {012E1000-F331-11DB-8314-0800200C9A66} URL = hxxp://www.google.com/search?q={searchTerms}
BHO: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll [2015-11-18] (AVAST Software)
BHO: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2011-03-28] (Microsoft Corp.)
BHO: No Name -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> No File
BHO-x32: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll [2015-11-18] (AVAST Software)
BHO-x32: Pomocná služba pro přihlášení ke službě Windows Live ID -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2011-03-28] (Microsoft Corp.)
Toolbar: HKLM - No Name - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - No File
Toolbar: HKLM - No Name - {CC1A175A-E45B-41ED-A30C-C9B1D7A0C02F} - No File
FireFox:
========
FF ProfilePath: C:\Users\honza\AppData\Roaming\Mozilla\Firefox\Profiles\wh42cenw.default
FF Homepage: hxxp://www.seznam.cz/
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_20_0_0_267.dll [2016-01-02] ()
FF Plugin: @microsoft.com/GENUINE -> C:\Windows\system32\Wat\npWatWeb.dll [2011-09-19] (Microsoft Corporation)
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.41105.0\npctrl.dll [2015-11-04] ( Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_20_0_0_267.dll [2016-01-02] ()
FF Plugin-x32: @adobe.com/ShockwavePlayer -> C:\Windows\SysWOW64\Adobe\Director\np32dsw_1222172.dll [2015-11-19] (Adobe Systems, Inc.)
FF Plugin-x32: @Google.com/GoogleEarthPlugin -> C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll [2013-10-07] (Google)
FF Plugin-x32: @microsoft.com/GENUINE -> C:\Windows\system32\Wat\npWatWeb.dll [2011-09-19] (Microsoft Corporation)
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\5.1.41105.0\npctrl.dll [2015-11-04] ( Microsoft Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.29.1\npGoogleUpdate3.dll [2015-12-06] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.29.1\npGoogleUpdate3.dll [2015-12-06] (Google Inc.)
FF Plugin-x32: @videolan.org/vlc,version=2.0.5 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2015-04-13] (VideoLAN)
FF Plugin-x32: @videolan.org/vlc,version=2.1.0 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2015-04-13] (VideoLAN)
FF Plugin-x32: @videolan.org/vlc,version=2.1.1 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2015-04-13] (VideoLAN)
FF Plugin-x32: @videolan.org/vlc,version=2.1.2 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2015-04-13] (VideoLAN)
FF Plugin-x32: @videolan.org/vlc,version=2.1.3 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2015-04-13] (VideoLAN)
FF Plugin-x32: @videolan.org/vlc,version=2.1.5 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2015-04-13] (VideoLAN)
FF Plugin-x32: @videolan.org/vlc,version=2.2.1 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2015-04-13] (VideoLAN)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll [2015-09-30] (Adobe Systems Inc.)
FF Plugin HKU\S-1-5-21-866132977-3524765048-2583430549-1000: @tools.google.com/Google Update;version=3 -> C:\Users\honza\AppData\Local\Google\Update\1.3.22.3\npGoogleUpdate3.dll [2013-12-07] (Google Inc.)
FF Plugin HKU\S-1-5-21-866132977-3524765048-2583430549-1000: @tools.google.com/Google Update;version=9 -> C:\Users\honza\AppData\Local\Google\Update\1.3.22.3\npGoogleUpdate3.dll [2013-12-07] (Google Inc.)
FF Plugin HKU\S-1-5-21-866132977-3524765048-2583430549-1000: ubisoft.com/uplaypc -> C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\npuplaypc.dll [No File]
FF user.js: detected! => C:\Users\honza\AppData\Roaming\Mozilla\Firefox\Profiles\wh42cenw.default\user.js [2015-12-07]
FF Extension: Money Viking - C:\Users\honza\AppData\Roaming\Mozilla\Firefox\Profiles\wh42cenw.default\Extensions\{8ef52718-ef02-42dc-991a-dd0e9f7bbf20}.xpi [2015-12-06] [not signed]
FF HKLM-x32\...\Firefox\Extensions: [wrc@avast.com] - C:\Program Files\AVAST Software\Avast\WebRep\FF
FF Extension: Avast Online Security - C:\Program Files\AVAST Software\Avast\WebRep\FF [2015-12-06]
FF HKLM-x32\...\Firefox\Extensions: [sp@avast.com] - C:\Program Files\AVAST Software\Avast\SafePrice\FF
FF Extension: Avast SafePrice - C:\Program Files\AVAST Software\Avast\SafePrice\FF [2015-12-06]
Chrome:
=======
CHR HomePage: Default -> hxxp://www.seznam.cz/
CHR Session Restore: Default -> is enabled.
CHR Profile: C:\Users\honza\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (Prezentace Google) - C:\Users\honza\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2015-04-08]
CHR Extension: (Dokumenty Google) - C:\Users\honza\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2015-04-09]
CHR Extension: (Disk Google) - C:\Users\honza\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2015-10-22]
CHR Extension: (YouTube) - C:\Users\honza\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2015-09-24]
CHR Extension: (Vyhledávání Google) - C:\Users\honza\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2015-10-29]
CHR Extension: (Tabulky Google) - C:\Users\honza\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2015-04-08]
CHR Extension: (Dokumenty Google offline) - C:\Users\honza\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2015-11-17]
CHR Extension: (Avast Online Security) - C:\Users\honza\AppData\Local\Google\Chrome\User Data\Default\Extensions\gomekmidlodglbbmalcneegieacbdmki [2015-11-07]
CHR Extension: (Platby Internetového obchodu Chrome) - C:\Users\honza\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2015-07-31]
CHR Extension: (Gmail) - C:\Users\honza\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2015-04-09]
CHR HKLM\...\Chrome\Extension: [flliilndjeohchalpbbcdekjklbdgfkk] - hxxps://clients2.google.com/service/update2/crx
CHR HKLM-x32\...\Chrome\Extension: [flliilndjeohchalpbbcdekjklbdgfkk] - hxxps://clients2.google.com/service/update2/crx
CHR HKLM-x32\...\Chrome\Extension: [gomekmidlodglbbmalcneegieacbdmki] - C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChrome.crx [2015-11-18]
StartMenuInternet: Google Chrome.B25RZPGWCXT6AHLMJWE2AJ4DJU - C:\Users\Guest\AppData\Local\Google\Chrome\Application\chrome.exe
==================== Services (Whitelisted) ========================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R2 !SASCORE; C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE [144152 2013-10-10] (SUPERAntiSpyware.com)
S3 ACDaemon; C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACService.exe [113152 2010-03-18] (ArcSoft Inc.)
R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [226440 2015-12-06] (AVAST Software)
S3 Disc Soft Lite Bus Service; C:\Program Files\DAEMON Tools Lite\DiscSoftBusService.exe [1272560 2015-05-21] (Disc Soft Ltd)
R2 DragonUpdater; C:\Program Files (x86)\Comodo\Dragon\dragon_updater.exe [2056376 2015-11-20] (Comodo)
R2 IDriverT; C:\Program Files (x86)\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe [69632 2005-04-03] (Macrovision Corporation) [File not signed]
S2 MBAMService; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe [1133880 2015-06-18] (Malwarebytes Corporation)
S3 ssinstall; C:\Windows\SysWOW64\ssins.exe [2317848 2013-03-03] ()
R2 uCamMonitor; C:\Program Files (x86)\ArcSoft\Magic-i Visual Effects 2\uCamMonitor.exe [104960 2008-09-18] (ArcSoft, Inc.)
S3 VCFw; C:\Program Files (x86)\Common Files\Sony Shared\VAIO Content Folder Watcher\VCFw.exe [851824 2010-06-17] (Sony Corporation)
S3 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2009-07-14] (Microsoft Corporation)
S3 AvastVBoxSvc; C:\Program Files\AVAST Software\Avast\ng\vbox\AvastVBoxSVC.exe [X]
===================== Drivers (Whitelisted) ==========================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R3 ArcSoftKsUFilter; C:\Windows\System32\DRIVERS\ArcSoftKsUFilter.sys [19968 2009-05-26] (ArcSoft, Inc.)
R2 aswHwid; C:\Windows\system32\drivers\aswHwid.sys [28656 2015-12-06] (AVAST Software)
R2 aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [97648 2015-12-19] (AVAST Software)
R1 aswRdr; C:\Windows\system32\drivers\aswRdr2.sys [93528 2015-12-06] (AVAST Software)
R0 aswRvrt; C:\Windows\System32\Drivers\aswRvrt.sys [65224 2015-12-06] (AVAST Software)
R1 aswSnx; C:\Windows\system32\drivers\aswSnx.sys [1055560 2015-12-06] (AVAST Software)
R1 aswSP; C:\Windows\system32\drivers\aswSP.sys [451040 2015-12-19] (AVAST Software)
S2 aswStm; C:\Windows\system32\drivers\aswStm.sys [155304 2015-12-06] (AVAST Software)
R0 aswVmm; C:\Windows\System32\Drivers\aswVmm.sys [273784 2015-12-06] (AVAST Software)
R3 dtlitescsibus; C:\Windows\System32\DRIVERS\dtlitescsibus.sys [30264 2015-06-17] (Disc Soft Ltd)
S3 ebdrv; C:\Windows\system32\drivers\evbda.sys [3286016 2009-06-10] (Broadcom Corporation)
S3 igfx; C:\Windows\System32\DRIVERS\igdkmd64.sys [10326784 2010-06-24] (Intel Corporation) [File not signed]
S3 IntcDAud; C:\Windows\System32\DRIVERS\IntcDAud.sys [271872 2010-06-24] (Intel(R) Corporation) [File not signed]
S3 massfilter_hs; C:\Windows\System32\drivers\massfilter_hs.sys [18456 2011-03-07] (HandSet Incorporated)
R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25816 2015-06-18] (Malwarebytes Corporation)
S3 MBAMWebAccessControl; C:\Windows\system32\drivers\mwac.sys [63704 2015-06-18] (Malwarebytes Corporation)
R1 SASDIFSV; C:\Program Files\SUPERAntiSpyware\SASDIFSV64.SYS [14928 2011-07-22] (SUPERAdBlocker.com and SUPERAntiSpyware.com)
R1 SASKUTIL; C:\Program Files\SUPERAntiSpyware\SASKUTIL64.SYS [12368 2011-07-12] (SUPERAdBlocker.com and SUPERAntiSpyware.com)
S4 sfdrv01; C:\Windows\System32\drivers\sfdrv01.sys [69120 2006-03-26] (Protection Technology (StarForce)) [File not signed]
S4 sfhlp02; C:\Windows\System32\drivers\sfhlp02.sys [7168 2006-03-13] (Protection Technology (StarForce)) [File not signed]
S3 ew_hwusbdev; system32\DRIVERS\ew_hwusbdev.sys [X]
S3 ew_usbenumfilter; system32\DRIVERS\ew_usbenumfilter.sys [X]
S3 Huawei; system32\DRIVERS\ewdcsc.sys [X]
S3 huawei_cdcacm; system32\DRIVERS\ew_jucdcacm.sys [X]
S3 huawei_enumerator; system32\DRIVERS\ew_jubusenum.sys [X]
S3 huawei_ext_ctrl; system32\DRIVERS\ew_juextctrl.sys [X]
S3 huawei_wwanecm; system32\DRIVERS\ew_juwwanecm.sys [X]
S3 hwdatacard; system32\DRIVERS\ewusbmdm.sys [X]
S3 NLNdisMP; system32\DRIVERS\nlndis.sys [X]
S3 NLNdisPT; system32\DRIVERS\nlndis.sys [X]
U4 VBoxAswDrv; \??\C:\Program Files\AVAST Software\Avast\ng\vbox\VBoxAswDrv.sys [X]
S3 vserial; System32\DRIVERS\vserial.sys [X]
S3 WinRing0_1_2_0; \??\C:\Program Files (x86)\BatteryCare\WinRing0x64.sys [X]
==================== NetSvcs (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
==================== One Month Created files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2016-01-02 21:53 - 2016-01-02 21:53 - 00016928 ____C C:\Users\honza\Desktop\FRST.txt
2016-01-02 21:53 - 2016-01-02 21:53 - 00000000 ___DC C:\FRST
2016-01-02 21:48 - 2016-01-02 21:48 - 02370560 ____C (Farbar) C:\Users\honza\Desktop\FRST64.exe
2016-01-02 15:32 - 2016-01-02 15:35 - 00000000 ___DC C:\Users\honza\Downloads\série 5 (7.ep)
2016-01-02 15:21 - 2016-01-02 16:09 - 00000000 ___DC C:\Users\honza\Downloads\Ancient Discoveries serie 1
2016-01-02 14:35 - 2016-01-02 14:36 - 00000000 ___DC C:\Users\honza\Downloads\Na ostrově s Bearem Gryllsem 1. Séria
2016-01-02 13:27 - 2016-01-02 13:29 - 00000000 ___DC C:\Users\honza\Downloads\The Martian 2015 720p BluRay x264-88keyz
2016-01-02 13:12 - 2016-01-02 21:32 - 00000914 ____C C:\Windows\Tasks\Adobe Flash Player Updater.job
2016-01-02 13:12 - 2016-01-02 13:13 - 00003852 ____C C:\Windows\System32\Tasks\Adobe Flash Player Updater
2015-12-28 14:46 - 2015-12-28 14:46 - 00121680 ____C C:\Users\honza\AppData\Local\GDIPFONTCACHEV1.DAT
2015-12-17 12:44 - 2015-12-17 12:45 - 00461784 ____C C:\Windows\system32\FNTCACHE.DAT
2015-12-07 14:04 - 2015-12-07 14:04 - 00000000 ___DC C:\Users\honza\AppData\Roaming\MAGIX
2015-12-07 14:04 - 2015-12-07 14:04 - 00000000 ___DC C:\ProgramData\MAGIX
2015-12-07 14:00 - 2015-12-07 14:05 - 00000000 ___DC C:\ProgramData\simplitec
2015-12-07 14:00 - 2015-05-06 16:54 - 00120200 ____C () C:\Windows\SysWOW64\DLLDEV32i.dll
2015-12-07 13:47 - 2015-12-07 13:47 - 00000000 ___DC C:\ProgramData\12bfc3a0-7ee7-1
2015-12-07 13:47 - 2015-12-07 13:47 - 00000000 ___DC C:\ProgramData\12bfc3a0-6997-0
2015-12-06 12:45 - 2015-12-06 12:45 - 00386096 ____C (AVAST Software) C:\Windows\system32\aswBoot.exe
2015-12-06 12:45 - 2015-12-06 12:45 - 00043112 ____C (AVAST Software) C:\Windows\avastSS.scr
2015-12-04 14:37 - 2015-12-04 14:37 - 00000000 ___DC C:\Windows\System32\Tasks\AVAST Software
2015-12-04 14:37 - 2015-12-04 14:37 - 00000000 ___DC C:\Program Files\Common Files\AV
2015-12-03 14:59 - 2015-12-03 14:59 - 00000000 ___DC C:\Users\honza\AppData\Local\CEF
==================== One Month Modified files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2016-01-02 21:53 - 2009-07-14 04:20 - 00000000 ___DC C:\Windows
2016-01-02 21:44 - 2013-10-12 07:20 - 00000952 ____C C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2016-01-02 21:19 - 2015-10-15 09:51 - 00000958 ____C C:\Windows\Tasks\Adobe Flash Player PPAPI Notifier.job
2016-01-02 19:09 - 2009-07-14 05:45 - 00015984 ___HC C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2016-01-02 19:09 - 2009-07-14 05:45 - 00015984 ___HC C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2016-01-02 19:06 - 2010-10-14 21:36 - 00667902 ____C C:\Windows\system32\perfh005.dat
2016-01-02 19:06 - 2010-10-14 21:36 - 00141048 ____C C:\Windows\system32\perfc005.dat
2016-01-02 19:06 - 2009-07-14 06:13 - 01581054 ____C C:\Windows\system32\PerfStringBackup.INI
2016-01-02 19:06 - 2009-07-14 04:20 - 00000000 ___DC C:\Windows\inf
2016-01-02 19:05 - 2013-01-22 14:16 - 00000000 __RDC C:\Users\honza\Desktop\Nová složka
2016-01-02 19:02 - 2013-10-12 07:20 - 00000948 ____C C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2016-01-02 19:02 - 2009-07-14 06:08 - 00000006 ___HC C:\Windows\Tasks\SA.DAT
2016-01-02 19:01 - 2013-03-15 03:04 - 00000000 ___DC C:\Program Files\Microsoft Silverlight
2016-01-02 19:01 - 2013-03-15 03:04 - 00000000 ___DC C:\Program Files (x86)\Microsoft Silverlight
2016-01-02 17:26 - 2013-05-30 23:42 - 00000000 ___DC C:\Users\honza\AppData\Roaming\uTorrent
2016-01-02 14:36 - 2013-01-30 15:22 - 00000000 ___DC C:\Users\honza\AppData\Roaming\vlc
2016-01-02 13:22 - 2013-03-15 03:06 - 00000000 ___DC C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Silverlight
2016-01-02 13:21 - 2013-07-15 02:01 - 00000000 ___DC C:\Windows\system32\MRT
2016-01-02 13:13 - 2013-03-02 03:37 - 00796864 ____C (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2016-01-02 13:13 - 2012-01-25 11:21 - 00142528 ____C (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2016-01-02 13:10 - 2011-10-25 00:52 - 140158008 ____C (Microsoft Corporation) C:\Windows\system32\MRT.exe
2015-12-27 14:09 - 2013-11-13 00:19 - 00004182 ____C C:\Windows\System32\Tasks\avast! Emergency Update
2015-12-21 18:08 - 2015-05-12 13:00 - 00000000 ___DC C:\Users\honza\AppData\Local\CrashDumps
2015-12-19 08:55 - 2013-11-27 14:16 - 00451040 ____C (AVAST Software) C:\Windows\system32\Drivers\aswsp.sys
2015-12-19 08:55 - 2013-11-27 14:16 - 00097648 ____C (AVAST Software) C:\Windows\system32\Drivers\aswmonflt.sys
2015-12-14 20:46 - 2015-07-07 02:36 - 00000000 ___DC C:\Users\honza\AppData\Roaming\Media Player Classic
2015-12-07 14:00 - 2015-09-23 13:10 - 00000000 ___DC C:\ProgramData\Package Cache
2015-12-06 19:35 - 2015-01-27 07:40 - 00000000 ___DC C:\Users\honza\knihovna
2015-12-06 12:45 - 2014-04-26 20:47 - 00028656 ____C (AVAST Software) C:\Windows\system32\Drivers\aswHwid.sys
2015-12-06 12:45 - 2013-12-26 20:56 - 00155304 ____C (AVAST Software) C:\Windows\system32\Drivers\aswStm.sys
2015-12-06 12:45 - 2013-11-27 14:16 - 01055560 ____C (AVAST Software) C:\Windows\system32\Drivers\aswSnx.sys
2015-12-06 12:45 - 2013-11-27 14:16 - 00273784 ____C (AVAST Software) C:\Windows\system32\Drivers\aswVmm.sys
2015-12-06 12:45 - 2013-11-27 14:16 - 00065224 ____C (AVAST Software) C:\Windows\system32\Drivers\aswRvrt.sys
2015-12-06 12:45 - 2013-11-27 14:15 - 00093528 ____C (AVAST Software) C:\Windows\system32\Drivers\aswRdr2.sys
2015-12-06 12:39 - 2011-09-16 23:42 - 00003948 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA
2015-12-06 12:39 - 2011-09-16 23:42 - 00003696 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore
2015-12-04 22:28 - 2012-11-13 15:44 - 00000000 ___DC C:\Hry
2015-12-03 15:06 - 2015-11-01 18:11 - 00002441 ____C C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Acrobat Reader DC.lnk
2015-12-03 14:59 - 2014-07-09 09:59 - 00000000 ___DC C:\Users\honza\AppData\Local\Adobe
==================== Files in the root of some directories =======
2002-08-29 18:33 - 2002-08-29 18:33 - 0319488 ___RC () C:\Users\honza\AppData\Roaming\MafiaSetup.exe
2013-12-12 23:47 - 2013-12-12 23:48 - 0039073 ____C () C:\Users\honza\AppData\Local\Perfmon.PerfmonCfg
2013-11-27 23:06 - 2013-11-27 23:06 - 0007668 ____C () C:\Users\honza\AppData\Local\Resmon.ResmonCfg
2015-06-01 18:25 - 2015-06-01 18:25 - 0000000 ____C () C:\Users\honza\AppData\Local\{2136A391-B028-47DF-A112-8FCA991D85B2}
2013-09-06 22:07 - 2013-09-06 22:07 - 0030621 ____C () C:\ProgramData\1378501603.bdinstall.bin
2013-09-06 22:08 - 2013-09-06 22:08 - 0029600 ____C () C:\ProgramData\1378501699.1000.bin
2013-09-06 22:08 - 2013-09-06 22:08 - 0000798 ____C () C:\ProgramData\1378501699.2376.bin
2013-09-06 22:08 - 2013-09-06 22:08 - 0002052 ____C () C:\ProgramData\1378501699.4508.bin
2013-09-06 22:10 - 2013-09-06 22:10 - 0030489 ____C () C:\ProgramData\1378501837.bdinstall.bin
2013-09-06 22:19 - 2013-09-06 22:19 - 0195664 ____C () C:\ProgramData\1378502170.bdinstall.bin
2013-10-07 09:58 - 2013-10-07 09:58 - 0022988 ____C () C:\ProgramData\1381136314.bdinstall.bin
2013-10-07 10:01 - 2013-10-07 10:01 - 0079615 ____C () C:\ProgramData\1381136320.bdinstall.bin
2013-11-02 13:49 - 2013-11-02 13:49 - 0229590 ____C () C:\ProgramData\1383396454.bdinstall.bin
2013-11-02 13:53 - 2013-11-02 13:53 - 0037592 ____C () C:\ProgramData\1383396818.bdinstall.bin
2013-11-02 14:14 - 2013-11-02 14:14 - 0174510 ____C () C:\ProgramData\1383396823.bdinstall.bin
2013-11-02 14:37 - 2013-11-02 14:37 - 0037842 ____C () C:\ProgramData\1383399436.bdinstall.bin
2013-11-02 14:38 - 2013-11-02 14:38 - 0095257 ____C () C:\ProgramData\1383399441.bdinstall.bin
==================== Bamital & volsnap =================
(There is no automatic fix for files that do not pass verification.)
C:\Windows\system32\winlogon.exe => File is digitally signed
C:\Windows\system32\wininit.exe => File is digitally signed
C:\Windows\SysWOW64\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\system32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\system32\services.exe => File is digitally signed
C:\Windows\system32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\system32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\system32\rpcss.dll => File is digitally signed
C:\Windows\system32\dnsapi.dll => File is digitally signed
C:\Windows\SysWOW64\dnsapi.dll => File is digitally signed
C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed
LastRegBack: 2016-01-02 15:50
==================== End of FRST.txt ============================
Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version:31-12-2015
Ran by honza (administrator) on MARTIN (02-01-2016 21:53:21)
Running from C:\Users\honza\Desktop
Loaded Profiles: honza (Available Profiles: honza & Guest)
Platform: Windows 7 Home Premium (X64) Language: Čeština (Česká republika)
Internet Explorer Version 9 (Default browser: Chrome)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/33 ... scan-tool/
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(AMD) C:\Windows\System32\atiesrxx.exe
(AMD) C:\Windows\System32\atieclxx.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe
(SUPERAntiSpyware.com) C:\Program Files\SUPERAntiSpyware\SASCore64.exe
(Broadcom Corporation.) C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe
(Comodo) C:\Program Files (x86)\Comodo\Dragon\dragon_updater.exe
(Macrovision Corporation) C:\Program Files (x86)\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
(Google Inc.) C:\Program Files (x86)\Google\Update\1.3.29.1\GoogleCrashHandler.exe
(Google Inc.) C:\Program Files (x86)\Google\Update\1.3.29.1\GoogleCrashHandler64.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(ArcSoft, Inc.) C:\Program Files (x86)\ArcSoft\Magic-i Visual Effects 2\uCamMonitor.exe
(Sony Corporation) C:\Program Files\Sony\VAIO Power Management\SPMgr.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastUI.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
==================== Registry (Whitelisted) ===========================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM-x32\...\Run: [AvastUI.exe] => C:\Program Files\AVAST Software\Avast\AvastUI.exe [7021880 2015-12-06] (AVAST Software)
Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation)
HKU\S-1-5-21-866132977-3524765048-2583430549-1000\...\RunOnce: [FlashPlayerUpdate] => C:\Windows\SysWOW64\Macromed\Flash\FlashUtil32_19_0_0_245_pepper.exe [1158856 2015-12-02] (Adobe Systems Incorporated)
HKU\S-1-5-21-866132977-3524765048-2583430549-1000\...\MountPoints2: {e162d644-151a-11e5-b93d-ec55f9e929bb} - E:\setup.exe
HKU\S-1-5-21-866132977-3524765048-2583430549-1000\...\MountPoints2: {e162d647-151a-11e5-b93d-ec55f9e929bb} - G:\m.exe
HKU\S-1-5-21-866132977-3524765048-2583430549-1000\...\MountPoints2: {e17b9178-a0e5-11e4-a51d-ec55f9e929bb} - J:\HiSuiteDownLoader.exe
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - %SystemRoot%\system32\wpdshserviceobj.dll (Microsoft Corporation)
ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShA64.dll [2015-12-06] (AVAST Software)
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
Tcpip\Parameters: [DhcpNameServer] 192.168.43.1
Tcpip\..\Interfaces\{25559BA7-6EF9-45A1-8A74-5DE0661ACE12}: [DhcpNameServer] 192.168.42.129
Tcpip\..\Interfaces\{A3BBF46B-A159-4BF4-B070-5D52FC44EA02}: [DhcpNameServer] 10.0.0.138
Tcpip\..\Interfaces\{A54718C9-FD98-4D35-9BC5-17E8F314811B}: [DhcpNameServer] 192.168.100.254
Tcpip\..\Interfaces\{D814BF20-A917-41A7-BDAA-43E59F9CD8E7}: [DhcpNameServer] 192.168.42.129
Tcpip\..\Interfaces\{FCCB9CFF-7B76-46F5-A504-F6C1EE5BE0D5}: [DhcpNameServer] 192.168.43.1
Internet Explorer:
==================
HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Local Page =
SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-21-866132977-3524765048-2583430549-1000 -> {012E1000-F331-11DB-8314-0800200C9A66} URL = hxxp://www.google.com/search?q={searchTerms}
BHO: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll [2015-11-18] (AVAST Software)
BHO: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2011-03-28] (Microsoft Corp.)
BHO: No Name -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> No File
BHO-x32: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll [2015-11-18] (AVAST Software)
BHO-x32: Pomocná služba pro přihlášení ke službě Windows Live ID -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2011-03-28] (Microsoft Corp.)
Toolbar: HKLM - No Name - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - No File
Toolbar: HKLM - No Name - {CC1A175A-E45B-41ED-A30C-C9B1D7A0C02F} - No File
FireFox:
========
FF ProfilePath: C:\Users\honza\AppData\Roaming\Mozilla\Firefox\Profiles\wh42cenw.default
FF Homepage: hxxp://www.seznam.cz/
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_20_0_0_267.dll [2016-01-02] ()
FF Plugin: @microsoft.com/GENUINE -> C:\Windows\system32\Wat\npWatWeb.dll [2011-09-19] (Microsoft Corporation)
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.41105.0\npctrl.dll [2015-11-04] ( Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_20_0_0_267.dll [2016-01-02] ()
FF Plugin-x32: @adobe.com/ShockwavePlayer -> C:\Windows\SysWOW64\Adobe\Director\np32dsw_1222172.dll [2015-11-19] (Adobe Systems, Inc.)
FF Plugin-x32: @Google.com/GoogleEarthPlugin -> C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll [2013-10-07] (Google)
FF Plugin-x32: @microsoft.com/GENUINE -> C:\Windows\system32\Wat\npWatWeb.dll [2011-09-19] (Microsoft Corporation)
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\5.1.41105.0\npctrl.dll [2015-11-04] ( Microsoft Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.29.1\npGoogleUpdate3.dll [2015-12-06] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.29.1\npGoogleUpdate3.dll [2015-12-06] (Google Inc.)
FF Plugin-x32: @videolan.org/vlc,version=2.0.5 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2015-04-13] (VideoLAN)
FF Plugin-x32: @videolan.org/vlc,version=2.1.0 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2015-04-13] (VideoLAN)
FF Plugin-x32: @videolan.org/vlc,version=2.1.1 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2015-04-13] (VideoLAN)
FF Plugin-x32: @videolan.org/vlc,version=2.1.2 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2015-04-13] (VideoLAN)
FF Plugin-x32: @videolan.org/vlc,version=2.1.3 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2015-04-13] (VideoLAN)
FF Plugin-x32: @videolan.org/vlc,version=2.1.5 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2015-04-13] (VideoLAN)
FF Plugin-x32: @videolan.org/vlc,version=2.2.1 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2015-04-13] (VideoLAN)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll [2015-09-30] (Adobe Systems Inc.)
FF Plugin HKU\S-1-5-21-866132977-3524765048-2583430549-1000: @tools.google.com/Google Update;version=3 -> C:\Users\honza\AppData\Local\Google\Update\1.3.22.3\npGoogleUpdate3.dll [2013-12-07] (Google Inc.)
FF Plugin HKU\S-1-5-21-866132977-3524765048-2583430549-1000: @tools.google.com/Google Update;version=9 -> C:\Users\honza\AppData\Local\Google\Update\1.3.22.3\npGoogleUpdate3.dll [2013-12-07] (Google Inc.)
FF Plugin HKU\S-1-5-21-866132977-3524765048-2583430549-1000: ubisoft.com/uplaypc -> C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\npuplaypc.dll [No File]
FF user.js: detected! => C:\Users\honza\AppData\Roaming\Mozilla\Firefox\Profiles\wh42cenw.default\user.js [2015-12-07]
FF Extension: Money Viking - C:\Users\honza\AppData\Roaming\Mozilla\Firefox\Profiles\wh42cenw.default\Extensions\{8ef52718-ef02-42dc-991a-dd0e9f7bbf20}.xpi [2015-12-06] [not signed]
FF HKLM-x32\...\Firefox\Extensions: [wrc@avast.com] - C:\Program Files\AVAST Software\Avast\WebRep\FF
FF Extension: Avast Online Security - C:\Program Files\AVAST Software\Avast\WebRep\FF [2015-12-06]
FF HKLM-x32\...\Firefox\Extensions: [sp@avast.com] - C:\Program Files\AVAST Software\Avast\SafePrice\FF
FF Extension: Avast SafePrice - C:\Program Files\AVAST Software\Avast\SafePrice\FF [2015-12-06]
Chrome:
=======
CHR HomePage: Default -> hxxp://www.seznam.cz/
CHR Session Restore: Default -> is enabled.
CHR Profile: C:\Users\honza\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (Prezentace Google) - C:\Users\honza\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2015-04-08]
CHR Extension: (Dokumenty Google) - C:\Users\honza\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2015-04-09]
CHR Extension: (Disk Google) - C:\Users\honza\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2015-10-22]
CHR Extension: (YouTube) - C:\Users\honza\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2015-09-24]
CHR Extension: (Vyhledávání Google) - C:\Users\honza\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2015-10-29]
CHR Extension: (Tabulky Google) - C:\Users\honza\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2015-04-08]
CHR Extension: (Dokumenty Google offline) - C:\Users\honza\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2015-11-17]
CHR Extension: (Avast Online Security) - C:\Users\honza\AppData\Local\Google\Chrome\User Data\Default\Extensions\gomekmidlodglbbmalcneegieacbdmki [2015-11-07]
CHR Extension: (Platby Internetového obchodu Chrome) - C:\Users\honza\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2015-07-31]
CHR Extension: (Gmail) - C:\Users\honza\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2015-04-09]
CHR HKLM\...\Chrome\Extension: [flliilndjeohchalpbbcdekjklbdgfkk] - hxxps://clients2.google.com/service/update2/crx
CHR HKLM-x32\...\Chrome\Extension: [flliilndjeohchalpbbcdekjklbdgfkk] - hxxps://clients2.google.com/service/update2/crx
CHR HKLM-x32\...\Chrome\Extension: [gomekmidlodglbbmalcneegieacbdmki] - C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChrome.crx [2015-11-18]
StartMenuInternet: Google Chrome.B25RZPGWCXT6AHLMJWE2AJ4DJU - C:\Users\Guest\AppData\Local\Google\Chrome\Application\chrome.exe
==================== Services (Whitelisted) ========================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R2 !SASCORE; C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE [144152 2013-10-10] (SUPERAntiSpyware.com)
S3 ACDaemon; C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACService.exe [113152 2010-03-18] (ArcSoft Inc.)
R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [226440 2015-12-06] (AVAST Software)
S3 Disc Soft Lite Bus Service; C:\Program Files\DAEMON Tools Lite\DiscSoftBusService.exe [1272560 2015-05-21] (Disc Soft Ltd)
R2 DragonUpdater; C:\Program Files (x86)\Comodo\Dragon\dragon_updater.exe [2056376 2015-11-20] (Comodo)
R2 IDriverT; C:\Program Files (x86)\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe [69632 2005-04-03] (Macrovision Corporation) [File not signed]
S2 MBAMService; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe [1133880 2015-06-18] (Malwarebytes Corporation)
S3 ssinstall; C:\Windows\SysWOW64\ssins.exe [2317848 2013-03-03] ()
R2 uCamMonitor; C:\Program Files (x86)\ArcSoft\Magic-i Visual Effects 2\uCamMonitor.exe [104960 2008-09-18] (ArcSoft, Inc.)
S3 VCFw; C:\Program Files (x86)\Common Files\Sony Shared\VAIO Content Folder Watcher\VCFw.exe [851824 2010-06-17] (Sony Corporation)
S3 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2009-07-14] (Microsoft Corporation)
S3 AvastVBoxSvc; C:\Program Files\AVAST Software\Avast\ng\vbox\AvastVBoxSVC.exe [X]
===================== Drivers (Whitelisted) ==========================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R3 ArcSoftKsUFilter; C:\Windows\System32\DRIVERS\ArcSoftKsUFilter.sys [19968 2009-05-26] (ArcSoft, Inc.)
R2 aswHwid; C:\Windows\system32\drivers\aswHwid.sys [28656 2015-12-06] (AVAST Software)
R2 aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [97648 2015-12-19] (AVAST Software)
R1 aswRdr; C:\Windows\system32\drivers\aswRdr2.sys [93528 2015-12-06] (AVAST Software)
R0 aswRvrt; C:\Windows\System32\Drivers\aswRvrt.sys [65224 2015-12-06] (AVAST Software)
R1 aswSnx; C:\Windows\system32\drivers\aswSnx.sys [1055560 2015-12-06] (AVAST Software)
R1 aswSP; C:\Windows\system32\drivers\aswSP.sys [451040 2015-12-19] (AVAST Software)
S2 aswStm; C:\Windows\system32\drivers\aswStm.sys [155304 2015-12-06] (AVAST Software)
R0 aswVmm; C:\Windows\System32\Drivers\aswVmm.sys [273784 2015-12-06] (AVAST Software)
R3 dtlitescsibus; C:\Windows\System32\DRIVERS\dtlitescsibus.sys [30264 2015-06-17] (Disc Soft Ltd)
S3 ebdrv; C:\Windows\system32\drivers\evbda.sys [3286016 2009-06-10] (Broadcom Corporation)
S3 igfx; C:\Windows\System32\DRIVERS\igdkmd64.sys [10326784 2010-06-24] (Intel Corporation) [File not signed]
S3 IntcDAud; C:\Windows\System32\DRIVERS\IntcDAud.sys [271872 2010-06-24] (Intel(R) Corporation) [File not signed]
S3 massfilter_hs; C:\Windows\System32\drivers\massfilter_hs.sys [18456 2011-03-07] (HandSet Incorporated)
R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25816 2015-06-18] (Malwarebytes Corporation)
S3 MBAMWebAccessControl; C:\Windows\system32\drivers\mwac.sys [63704 2015-06-18] (Malwarebytes Corporation)
R1 SASDIFSV; C:\Program Files\SUPERAntiSpyware\SASDIFSV64.SYS [14928 2011-07-22] (SUPERAdBlocker.com and SUPERAntiSpyware.com)
R1 SASKUTIL; C:\Program Files\SUPERAntiSpyware\SASKUTIL64.SYS [12368 2011-07-12] (SUPERAdBlocker.com and SUPERAntiSpyware.com)
S4 sfdrv01; C:\Windows\System32\drivers\sfdrv01.sys [69120 2006-03-26] (Protection Technology (StarForce)) [File not signed]
S4 sfhlp02; C:\Windows\System32\drivers\sfhlp02.sys [7168 2006-03-13] (Protection Technology (StarForce)) [File not signed]
S3 ew_hwusbdev; system32\DRIVERS\ew_hwusbdev.sys [X]
S3 ew_usbenumfilter; system32\DRIVERS\ew_usbenumfilter.sys [X]
S3 Huawei; system32\DRIVERS\ewdcsc.sys [X]
S3 huawei_cdcacm; system32\DRIVERS\ew_jucdcacm.sys [X]
S3 huawei_enumerator; system32\DRIVERS\ew_jubusenum.sys [X]
S3 huawei_ext_ctrl; system32\DRIVERS\ew_juextctrl.sys [X]
S3 huawei_wwanecm; system32\DRIVERS\ew_juwwanecm.sys [X]
S3 hwdatacard; system32\DRIVERS\ewusbmdm.sys [X]
S3 NLNdisMP; system32\DRIVERS\nlndis.sys [X]
S3 NLNdisPT; system32\DRIVERS\nlndis.sys [X]
U4 VBoxAswDrv; \??\C:\Program Files\AVAST Software\Avast\ng\vbox\VBoxAswDrv.sys [X]
S3 vserial; System32\DRIVERS\vserial.sys [X]
S3 WinRing0_1_2_0; \??\C:\Program Files (x86)\BatteryCare\WinRing0x64.sys [X]
==================== NetSvcs (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
==================== One Month Created files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2016-01-02 21:53 - 2016-01-02 21:53 - 00016928 ____C C:\Users\honza\Desktop\FRST.txt
2016-01-02 21:53 - 2016-01-02 21:53 - 00000000 ___DC C:\FRST
2016-01-02 21:48 - 2016-01-02 21:48 - 02370560 ____C (Farbar) C:\Users\honza\Desktop\FRST64.exe
2016-01-02 15:32 - 2016-01-02 15:35 - 00000000 ___DC C:\Users\honza\Downloads\série 5 (7.ep)
2016-01-02 15:21 - 2016-01-02 16:09 - 00000000 ___DC C:\Users\honza\Downloads\Ancient Discoveries serie 1
2016-01-02 14:35 - 2016-01-02 14:36 - 00000000 ___DC C:\Users\honza\Downloads\Na ostrově s Bearem Gryllsem 1. Séria
2016-01-02 13:27 - 2016-01-02 13:29 - 00000000 ___DC C:\Users\honza\Downloads\The Martian 2015 720p BluRay x264-88keyz
2016-01-02 13:12 - 2016-01-02 21:32 - 00000914 ____C C:\Windows\Tasks\Adobe Flash Player Updater.job
2016-01-02 13:12 - 2016-01-02 13:13 - 00003852 ____C C:\Windows\System32\Tasks\Adobe Flash Player Updater
2015-12-28 14:46 - 2015-12-28 14:46 - 00121680 ____C C:\Users\honza\AppData\Local\GDIPFONTCACHEV1.DAT
2015-12-17 12:44 - 2015-12-17 12:45 - 00461784 ____C C:\Windows\system32\FNTCACHE.DAT
2015-12-07 14:04 - 2015-12-07 14:04 - 00000000 ___DC C:\Users\honza\AppData\Roaming\MAGIX
2015-12-07 14:04 - 2015-12-07 14:04 - 00000000 ___DC C:\ProgramData\MAGIX
2015-12-07 14:00 - 2015-12-07 14:05 - 00000000 ___DC C:\ProgramData\simplitec
2015-12-07 14:00 - 2015-05-06 16:54 - 00120200 ____C () C:\Windows\SysWOW64\DLLDEV32i.dll
2015-12-07 13:47 - 2015-12-07 13:47 - 00000000 ___DC C:\ProgramData\12bfc3a0-7ee7-1
2015-12-07 13:47 - 2015-12-07 13:47 - 00000000 ___DC C:\ProgramData\12bfc3a0-6997-0
2015-12-06 12:45 - 2015-12-06 12:45 - 00386096 ____C (AVAST Software) C:\Windows\system32\aswBoot.exe
2015-12-06 12:45 - 2015-12-06 12:45 - 00043112 ____C (AVAST Software) C:\Windows\avastSS.scr
2015-12-04 14:37 - 2015-12-04 14:37 - 00000000 ___DC C:\Windows\System32\Tasks\AVAST Software
2015-12-04 14:37 - 2015-12-04 14:37 - 00000000 ___DC C:\Program Files\Common Files\AV
2015-12-03 14:59 - 2015-12-03 14:59 - 00000000 ___DC C:\Users\honza\AppData\Local\CEF
==================== One Month Modified files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2016-01-02 21:53 - 2009-07-14 04:20 - 00000000 ___DC C:\Windows
2016-01-02 21:44 - 2013-10-12 07:20 - 00000952 ____C C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2016-01-02 21:19 - 2015-10-15 09:51 - 00000958 ____C C:\Windows\Tasks\Adobe Flash Player PPAPI Notifier.job
2016-01-02 19:09 - 2009-07-14 05:45 - 00015984 ___HC C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2016-01-02 19:09 - 2009-07-14 05:45 - 00015984 ___HC C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2016-01-02 19:06 - 2010-10-14 21:36 - 00667902 ____C C:\Windows\system32\perfh005.dat
2016-01-02 19:06 - 2010-10-14 21:36 - 00141048 ____C C:\Windows\system32\perfc005.dat
2016-01-02 19:06 - 2009-07-14 06:13 - 01581054 ____C C:\Windows\system32\PerfStringBackup.INI
2016-01-02 19:06 - 2009-07-14 04:20 - 00000000 ___DC C:\Windows\inf
2016-01-02 19:05 - 2013-01-22 14:16 - 00000000 __RDC C:\Users\honza\Desktop\Nová složka
2016-01-02 19:02 - 2013-10-12 07:20 - 00000948 ____C C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2016-01-02 19:02 - 2009-07-14 06:08 - 00000006 ___HC C:\Windows\Tasks\SA.DAT
2016-01-02 19:01 - 2013-03-15 03:04 - 00000000 ___DC C:\Program Files\Microsoft Silverlight
2016-01-02 19:01 - 2013-03-15 03:04 - 00000000 ___DC C:\Program Files (x86)\Microsoft Silverlight
2016-01-02 17:26 - 2013-05-30 23:42 - 00000000 ___DC C:\Users\honza\AppData\Roaming\uTorrent
2016-01-02 14:36 - 2013-01-30 15:22 - 00000000 ___DC C:\Users\honza\AppData\Roaming\vlc
2016-01-02 13:22 - 2013-03-15 03:06 - 00000000 ___DC C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Silverlight
2016-01-02 13:21 - 2013-07-15 02:01 - 00000000 ___DC C:\Windows\system32\MRT
2016-01-02 13:13 - 2013-03-02 03:37 - 00796864 ____C (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2016-01-02 13:13 - 2012-01-25 11:21 - 00142528 ____C (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2016-01-02 13:10 - 2011-10-25 00:52 - 140158008 ____C (Microsoft Corporation) C:\Windows\system32\MRT.exe
2015-12-27 14:09 - 2013-11-13 00:19 - 00004182 ____C C:\Windows\System32\Tasks\avast! Emergency Update
2015-12-21 18:08 - 2015-05-12 13:00 - 00000000 ___DC C:\Users\honza\AppData\Local\CrashDumps
2015-12-19 08:55 - 2013-11-27 14:16 - 00451040 ____C (AVAST Software) C:\Windows\system32\Drivers\aswsp.sys
2015-12-19 08:55 - 2013-11-27 14:16 - 00097648 ____C (AVAST Software) C:\Windows\system32\Drivers\aswmonflt.sys
2015-12-14 20:46 - 2015-07-07 02:36 - 00000000 ___DC C:\Users\honza\AppData\Roaming\Media Player Classic
2015-12-07 14:00 - 2015-09-23 13:10 - 00000000 ___DC C:\ProgramData\Package Cache
2015-12-06 19:35 - 2015-01-27 07:40 - 00000000 ___DC C:\Users\honza\knihovna
2015-12-06 12:45 - 2014-04-26 20:47 - 00028656 ____C (AVAST Software) C:\Windows\system32\Drivers\aswHwid.sys
2015-12-06 12:45 - 2013-12-26 20:56 - 00155304 ____C (AVAST Software) C:\Windows\system32\Drivers\aswStm.sys
2015-12-06 12:45 - 2013-11-27 14:16 - 01055560 ____C (AVAST Software) C:\Windows\system32\Drivers\aswSnx.sys
2015-12-06 12:45 - 2013-11-27 14:16 - 00273784 ____C (AVAST Software) C:\Windows\system32\Drivers\aswVmm.sys
2015-12-06 12:45 - 2013-11-27 14:16 - 00065224 ____C (AVAST Software) C:\Windows\system32\Drivers\aswRvrt.sys
2015-12-06 12:45 - 2013-11-27 14:15 - 00093528 ____C (AVAST Software) C:\Windows\system32\Drivers\aswRdr2.sys
2015-12-06 12:39 - 2011-09-16 23:42 - 00003948 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA
2015-12-06 12:39 - 2011-09-16 23:42 - 00003696 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore
2015-12-04 22:28 - 2012-11-13 15:44 - 00000000 ___DC C:\Hry
2015-12-03 15:06 - 2015-11-01 18:11 - 00002441 ____C C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Acrobat Reader DC.lnk
2015-12-03 14:59 - 2014-07-09 09:59 - 00000000 ___DC C:\Users\honza\AppData\Local\Adobe
==================== Files in the root of some directories =======
2002-08-29 18:33 - 2002-08-29 18:33 - 0319488 ___RC () C:\Users\honza\AppData\Roaming\MafiaSetup.exe
2013-12-12 23:47 - 2013-12-12 23:48 - 0039073 ____C () C:\Users\honza\AppData\Local\Perfmon.PerfmonCfg
2013-11-27 23:06 - 2013-11-27 23:06 - 0007668 ____C () C:\Users\honza\AppData\Local\Resmon.ResmonCfg
2015-06-01 18:25 - 2015-06-01 18:25 - 0000000 ____C () C:\Users\honza\AppData\Local\{2136A391-B028-47DF-A112-8FCA991D85B2}
2013-09-06 22:07 - 2013-09-06 22:07 - 0030621 ____C () C:\ProgramData\1378501603.bdinstall.bin
2013-09-06 22:08 - 2013-09-06 22:08 - 0029600 ____C () C:\ProgramData\1378501699.1000.bin
2013-09-06 22:08 - 2013-09-06 22:08 - 0000798 ____C () C:\ProgramData\1378501699.2376.bin
2013-09-06 22:08 - 2013-09-06 22:08 - 0002052 ____C () C:\ProgramData\1378501699.4508.bin
2013-09-06 22:10 - 2013-09-06 22:10 - 0030489 ____C () C:\ProgramData\1378501837.bdinstall.bin
2013-09-06 22:19 - 2013-09-06 22:19 - 0195664 ____C () C:\ProgramData\1378502170.bdinstall.bin
2013-10-07 09:58 - 2013-10-07 09:58 - 0022988 ____C () C:\ProgramData\1381136314.bdinstall.bin
2013-10-07 10:01 - 2013-10-07 10:01 - 0079615 ____C () C:\ProgramData\1381136320.bdinstall.bin
2013-11-02 13:49 - 2013-11-02 13:49 - 0229590 ____C () C:\ProgramData\1383396454.bdinstall.bin
2013-11-02 13:53 - 2013-11-02 13:53 - 0037592 ____C () C:\ProgramData\1383396818.bdinstall.bin
2013-11-02 14:14 - 2013-11-02 14:14 - 0174510 ____C () C:\ProgramData\1383396823.bdinstall.bin
2013-11-02 14:37 - 2013-11-02 14:37 - 0037842 ____C () C:\ProgramData\1383399436.bdinstall.bin
2013-11-02 14:38 - 2013-11-02 14:38 - 0095257 ____C () C:\ProgramData\1383399441.bdinstall.bin
==================== Bamital & volsnap =================
(There is no automatic fix for files that do not pass verification.)
C:\Windows\system32\winlogon.exe => File is digitally signed
C:\Windows\system32\wininit.exe => File is digitally signed
C:\Windows\SysWOW64\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\system32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\system32\services.exe => File is digitally signed
C:\Windows\system32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\system32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\system32\rpcss.dll => File is digitally signed
C:\Windows\system32\dnsapi.dll => File is digitally signed
C:\Windows\SysWOW64\dnsapi.dll => File is digitally signed
C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed
LastRegBack: 2016-01-02 15:50
==================== End of FRST.txt ============================
Ran by honza (administrator) on MARTIN (02-01-2016 21:53:21)
Running from C:\Users\honza\Desktop
Loaded Profiles: honza (Available Profiles: honza & Guest)
Platform: Windows 7 Home Premium (X64) Language: Čeština (Česká republika)
Internet Explorer Version 9 (Default browser: Chrome)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/33 ... scan-tool/
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(AMD) C:\Windows\System32\atiesrxx.exe
(AMD) C:\Windows\System32\atieclxx.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe
(SUPERAntiSpyware.com) C:\Program Files\SUPERAntiSpyware\SASCore64.exe
(Broadcom Corporation.) C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe
(Comodo) C:\Program Files (x86)\Comodo\Dragon\dragon_updater.exe
(Macrovision Corporation) C:\Program Files (x86)\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
(Google Inc.) C:\Program Files (x86)\Google\Update\1.3.29.1\GoogleCrashHandler.exe
(Google Inc.) C:\Program Files (x86)\Google\Update\1.3.29.1\GoogleCrashHandler64.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(ArcSoft, Inc.) C:\Program Files (x86)\ArcSoft\Magic-i Visual Effects 2\uCamMonitor.exe
(Sony Corporation) C:\Program Files\Sony\VAIO Power Management\SPMgr.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastUI.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
==================== Registry (Whitelisted) ===========================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM-x32\...\Run: [AvastUI.exe] => C:\Program Files\AVAST Software\Avast\AvastUI.exe [7021880 2015-12-06] (AVAST Software)
Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation)
HKU\S-1-5-21-866132977-3524765048-2583430549-1000\...\RunOnce: [FlashPlayerUpdate] => C:\Windows\SysWOW64\Macromed\Flash\FlashUtil32_19_0_0_245_pepper.exe [1158856 2015-12-02] (Adobe Systems Incorporated)
HKU\S-1-5-21-866132977-3524765048-2583430549-1000\...\MountPoints2: {e162d644-151a-11e5-b93d-ec55f9e929bb} - E:\setup.exe
HKU\S-1-5-21-866132977-3524765048-2583430549-1000\...\MountPoints2: {e162d647-151a-11e5-b93d-ec55f9e929bb} - G:\m.exe
HKU\S-1-5-21-866132977-3524765048-2583430549-1000\...\MountPoints2: {e17b9178-a0e5-11e4-a51d-ec55f9e929bb} - J:\HiSuiteDownLoader.exe
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - %SystemRoot%\system32\wpdshserviceobj.dll (Microsoft Corporation)
ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShA64.dll [2015-12-06] (AVAST Software)
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
Tcpip\Parameters: [DhcpNameServer] 192.168.43.1
Tcpip\..\Interfaces\{25559BA7-6EF9-45A1-8A74-5DE0661ACE12}: [DhcpNameServer] 192.168.42.129
Tcpip\..\Interfaces\{A3BBF46B-A159-4BF4-B070-5D52FC44EA02}: [DhcpNameServer] 10.0.0.138
Tcpip\..\Interfaces\{A54718C9-FD98-4D35-9BC5-17E8F314811B}: [DhcpNameServer] 192.168.100.254
Tcpip\..\Interfaces\{D814BF20-A917-41A7-BDAA-43E59F9CD8E7}: [DhcpNameServer] 192.168.42.129
Tcpip\..\Interfaces\{FCCB9CFF-7B76-46F5-A504-F6C1EE5BE0D5}: [DhcpNameServer] 192.168.43.1
Internet Explorer:
==================
HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Local Page =
SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-21-866132977-3524765048-2583430549-1000 -> {012E1000-F331-11DB-8314-0800200C9A66} URL = hxxp://www.google.com/search?q={searchTerms}
BHO: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll [2015-11-18] (AVAST Software)
BHO: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2011-03-28] (Microsoft Corp.)
BHO: No Name -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> No File
BHO-x32: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll [2015-11-18] (AVAST Software)
BHO-x32: Pomocná služba pro přihlášení ke službě Windows Live ID -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2011-03-28] (Microsoft Corp.)
Toolbar: HKLM - No Name - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - No File
Toolbar: HKLM - No Name - {CC1A175A-E45B-41ED-A30C-C9B1D7A0C02F} - No File
FireFox:
========
FF ProfilePath: C:\Users\honza\AppData\Roaming\Mozilla\Firefox\Profiles\wh42cenw.default
FF Homepage: hxxp://www.seznam.cz/
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_20_0_0_267.dll [2016-01-02] ()
FF Plugin: @microsoft.com/GENUINE -> C:\Windows\system32\Wat\npWatWeb.dll [2011-09-19] (Microsoft Corporation)
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.41105.0\npctrl.dll [2015-11-04] ( Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_20_0_0_267.dll [2016-01-02] ()
FF Plugin-x32: @adobe.com/ShockwavePlayer -> C:\Windows\SysWOW64\Adobe\Director\np32dsw_1222172.dll [2015-11-19] (Adobe Systems, Inc.)
FF Plugin-x32: @Google.com/GoogleEarthPlugin -> C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll [2013-10-07] (Google)
FF Plugin-x32: @microsoft.com/GENUINE -> C:\Windows\system32\Wat\npWatWeb.dll [2011-09-19] (Microsoft Corporation)
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\5.1.41105.0\npctrl.dll [2015-11-04] ( Microsoft Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.29.1\npGoogleUpdate3.dll [2015-12-06] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.29.1\npGoogleUpdate3.dll [2015-12-06] (Google Inc.)
FF Plugin-x32: @videolan.org/vlc,version=2.0.5 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2015-04-13] (VideoLAN)
FF Plugin-x32: @videolan.org/vlc,version=2.1.0 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2015-04-13] (VideoLAN)
FF Plugin-x32: @videolan.org/vlc,version=2.1.1 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2015-04-13] (VideoLAN)
FF Plugin-x32: @videolan.org/vlc,version=2.1.2 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2015-04-13] (VideoLAN)
FF Plugin-x32: @videolan.org/vlc,version=2.1.3 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2015-04-13] (VideoLAN)
FF Plugin-x32: @videolan.org/vlc,version=2.1.5 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2015-04-13] (VideoLAN)
FF Plugin-x32: @videolan.org/vlc,version=2.2.1 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2015-04-13] (VideoLAN)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll [2015-09-30] (Adobe Systems Inc.)
FF Plugin HKU\S-1-5-21-866132977-3524765048-2583430549-1000: @tools.google.com/Google Update;version=3 -> C:\Users\honza\AppData\Local\Google\Update\1.3.22.3\npGoogleUpdate3.dll [2013-12-07] (Google Inc.)
FF Plugin HKU\S-1-5-21-866132977-3524765048-2583430549-1000: @tools.google.com/Google Update;version=9 -> C:\Users\honza\AppData\Local\Google\Update\1.3.22.3\npGoogleUpdate3.dll [2013-12-07] (Google Inc.)
FF Plugin HKU\S-1-5-21-866132977-3524765048-2583430549-1000: ubisoft.com/uplaypc -> C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\npuplaypc.dll [No File]
FF user.js: detected! => C:\Users\honza\AppData\Roaming\Mozilla\Firefox\Profiles\wh42cenw.default\user.js [2015-12-07]
FF Extension: Money Viking - C:\Users\honza\AppData\Roaming\Mozilla\Firefox\Profiles\wh42cenw.default\Extensions\{8ef52718-ef02-42dc-991a-dd0e9f7bbf20}.xpi [2015-12-06] [not signed]
FF HKLM-x32\...\Firefox\Extensions: [wrc@avast.com] - C:\Program Files\AVAST Software\Avast\WebRep\FF
FF Extension: Avast Online Security - C:\Program Files\AVAST Software\Avast\WebRep\FF [2015-12-06]
FF HKLM-x32\...\Firefox\Extensions: [sp@avast.com] - C:\Program Files\AVAST Software\Avast\SafePrice\FF
FF Extension: Avast SafePrice - C:\Program Files\AVAST Software\Avast\SafePrice\FF [2015-12-06]
Chrome:
=======
CHR HomePage: Default -> hxxp://www.seznam.cz/
CHR Session Restore: Default -> is enabled.
CHR Profile: C:\Users\honza\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (Prezentace Google) - C:\Users\honza\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2015-04-08]
CHR Extension: (Dokumenty Google) - C:\Users\honza\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2015-04-09]
CHR Extension: (Disk Google) - C:\Users\honza\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2015-10-22]
CHR Extension: (YouTube) - C:\Users\honza\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2015-09-24]
CHR Extension: (Vyhledávání Google) - C:\Users\honza\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2015-10-29]
CHR Extension: (Tabulky Google) - C:\Users\honza\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2015-04-08]
CHR Extension: (Dokumenty Google offline) - C:\Users\honza\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2015-11-17]
CHR Extension: (Avast Online Security) - C:\Users\honza\AppData\Local\Google\Chrome\User Data\Default\Extensions\gomekmidlodglbbmalcneegieacbdmki [2015-11-07]
CHR Extension: (Platby Internetového obchodu Chrome) - C:\Users\honza\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2015-07-31]
CHR Extension: (Gmail) - C:\Users\honza\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2015-04-09]
CHR HKLM\...\Chrome\Extension: [flliilndjeohchalpbbcdekjklbdgfkk] - hxxps://clients2.google.com/service/update2/crx
CHR HKLM-x32\...\Chrome\Extension: [flliilndjeohchalpbbcdekjklbdgfkk] - hxxps://clients2.google.com/service/update2/crx
CHR HKLM-x32\...\Chrome\Extension: [gomekmidlodglbbmalcneegieacbdmki] - C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChrome.crx [2015-11-18]
StartMenuInternet: Google Chrome.B25RZPGWCXT6AHLMJWE2AJ4DJU - C:\Users\Guest\AppData\Local\Google\Chrome\Application\chrome.exe
==================== Services (Whitelisted) ========================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R2 !SASCORE; C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE [144152 2013-10-10] (SUPERAntiSpyware.com)
S3 ACDaemon; C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACService.exe [113152 2010-03-18] (ArcSoft Inc.)
R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [226440 2015-12-06] (AVAST Software)
S3 Disc Soft Lite Bus Service; C:\Program Files\DAEMON Tools Lite\DiscSoftBusService.exe [1272560 2015-05-21] (Disc Soft Ltd)
R2 DragonUpdater; C:\Program Files (x86)\Comodo\Dragon\dragon_updater.exe [2056376 2015-11-20] (Comodo)
R2 IDriverT; C:\Program Files (x86)\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe [69632 2005-04-03] (Macrovision Corporation) [File not signed]
S2 MBAMService; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe [1133880 2015-06-18] (Malwarebytes Corporation)
S3 ssinstall; C:\Windows\SysWOW64\ssins.exe [2317848 2013-03-03] ()
R2 uCamMonitor; C:\Program Files (x86)\ArcSoft\Magic-i Visual Effects 2\uCamMonitor.exe [104960 2008-09-18] (ArcSoft, Inc.)
S3 VCFw; C:\Program Files (x86)\Common Files\Sony Shared\VAIO Content Folder Watcher\VCFw.exe [851824 2010-06-17] (Sony Corporation)
S3 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2009-07-14] (Microsoft Corporation)
S3 AvastVBoxSvc; C:\Program Files\AVAST Software\Avast\ng\vbox\AvastVBoxSVC.exe [X]
===================== Drivers (Whitelisted) ==========================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R3 ArcSoftKsUFilter; C:\Windows\System32\DRIVERS\ArcSoftKsUFilter.sys [19968 2009-05-26] (ArcSoft, Inc.)
R2 aswHwid; C:\Windows\system32\drivers\aswHwid.sys [28656 2015-12-06] (AVAST Software)
R2 aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [97648 2015-12-19] (AVAST Software)
R1 aswRdr; C:\Windows\system32\drivers\aswRdr2.sys [93528 2015-12-06] (AVAST Software)
R0 aswRvrt; C:\Windows\System32\Drivers\aswRvrt.sys [65224 2015-12-06] (AVAST Software)
R1 aswSnx; C:\Windows\system32\drivers\aswSnx.sys [1055560 2015-12-06] (AVAST Software)
R1 aswSP; C:\Windows\system32\drivers\aswSP.sys [451040 2015-12-19] (AVAST Software)
S2 aswStm; C:\Windows\system32\drivers\aswStm.sys [155304 2015-12-06] (AVAST Software)
R0 aswVmm; C:\Windows\System32\Drivers\aswVmm.sys [273784 2015-12-06] (AVAST Software)
R3 dtlitescsibus; C:\Windows\System32\DRIVERS\dtlitescsibus.sys [30264 2015-06-17] (Disc Soft Ltd)
S3 ebdrv; C:\Windows\system32\drivers\evbda.sys [3286016 2009-06-10] (Broadcom Corporation)
S3 igfx; C:\Windows\System32\DRIVERS\igdkmd64.sys [10326784 2010-06-24] (Intel Corporation) [File not signed]
S3 IntcDAud; C:\Windows\System32\DRIVERS\IntcDAud.sys [271872 2010-06-24] (Intel(R) Corporation) [File not signed]
S3 massfilter_hs; C:\Windows\System32\drivers\massfilter_hs.sys [18456 2011-03-07] (HandSet Incorporated)
R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25816 2015-06-18] (Malwarebytes Corporation)
S3 MBAMWebAccessControl; C:\Windows\system32\drivers\mwac.sys [63704 2015-06-18] (Malwarebytes Corporation)
R1 SASDIFSV; C:\Program Files\SUPERAntiSpyware\SASDIFSV64.SYS [14928 2011-07-22] (SUPERAdBlocker.com and SUPERAntiSpyware.com)
R1 SASKUTIL; C:\Program Files\SUPERAntiSpyware\SASKUTIL64.SYS [12368 2011-07-12] (SUPERAdBlocker.com and SUPERAntiSpyware.com)
S4 sfdrv01; C:\Windows\System32\drivers\sfdrv01.sys [69120 2006-03-26] (Protection Technology (StarForce)) [File not signed]
S4 sfhlp02; C:\Windows\System32\drivers\sfhlp02.sys [7168 2006-03-13] (Protection Technology (StarForce)) [File not signed]
S3 ew_hwusbdev; system32\DRIVERS\ew_hwusbdev.sys [X]
S3 ew_usbenumfilter; system32\DRIVERS\ew_usbenumfilter.sys [X]
S3 Huawei; system32\DRIVERS\ewdcsc.sys [X]
S3 huawei_cdcacm; system32\DRIVERS\ew_jucdcacm.sys [X]
S3 huawei_enumerator; system32\DRIVERS\ew_jubusenum.sys [X]
S3 huawei_ext_ctrl; system32\DRIVERS\ew_juextctrl.sys [X]
S3 huawei_wwanecm; system32\DRIVERS\ew_juwwanecm.sys [X]
S3 hwdatacard; system32\DRIVERS\ewusbmdm.sys [X]
S3 NLNdisMP; system32\DRIVERS\nlndis.sys [X]
S3 NLNdisPT; system32\DRIVERS\nlndis.sys [X]
U4 VBoxAswDrv; \??\C:\Program Files\AVAST Software\Avast\ng\vbox\VBoxAswDrv.sys [X]
S3 vserial; System32\DRIVERS\vserial.sys [X]
S3 WinRing0_1_2_0; \??\C:\Program Files (x86)\BatteryCare\WinRing0x64.sys [X]
==================== NetSvcs (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
==================== One Month Created files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2016-01-02 21:53 - 2016-01-02 21:53 - 00016928 ____C C:\Users\honza\Desktop\FRST.txt
2016-01-02 21:53 - 2016-01-02 21:53 - 00000000 ___DC C:\FRST
2016-01-02 21:48 - 2016-01-02 21:48 - 02370560 ____C (Farbar) C:\Users\honza\Desktop\FRST64.exe
2016-01-02 15:32 - 2016-01-02 15:35 - 00000000 ___DC C:\Users\honza\Downloads\série 5 (7.ep)
2016-01-02 15:21 - 2016-01-02 16:09 - 00000000 ___DC C:\Users\honza\Downloads\Ancient Discoveries serie 1
2016-01-02 14:35 - 2016-01-02 14:36 - 00000000 ___DC C:\Users\honza\Downloads\Na ostrově s Bearem Gryllsem 1. Séria
2016-01-02 13:27 - 2016-01-02 13:29 - 00000000 ___DC C:\Users\honza\Downloads\The Martian 2015 720p BluRay x264-88keyz
2016-01-02 13:12 - 2016-01-02 21:32 - 00000914 ____C C:\Windows\Tasks\Adobe Flash Player Updater.job
2016-01-02 13:12 - 2016-01-02 13:13 - 00003852 ____C C:\Windows\System32\Tasks\Adobe Flash Player Updater
2015-12-28 14:46 - 2015-12-28 14:46 - 00121680 ____C C:\Users\honza\AppData\Local\GDIPFONTCACHEV1.DAT
2015-12-17 12:44 - 2015-12-17 12:45 - 00461784 ____C C:\Windows\system32\FNTCACHE.DAT
2015-12-07 14:04 - 2015-12-07 14:04 - 00000000 ___DC C:\Users\honza\AppData\Roaming\MAGIX
2015-12-07 14:04 - 2015-12-07 14:04 - 00000000 ___DC C:\ProgramData\MAGIX
2015-12-07 14:00 - 2015-12-07 14:05 - 00000000 ___DC C:\ProgramData\simplitec
2015-12-07 14:00 - 2015-05-06 16:54 - 00120200 ____C () C:\Windows\SysWOW64\DLLDEV32i.dll
2015-12-07 13:47 - 2015-12-07 13:47 - 00000000 ___DC C:\ProgramData\12bfc3a0-7ee7-1
2015-12-07 13:47 - 2015-12-07 13:47 - 00000000 ___DC C:\ProgramData\12bfc3a0-6997-0
2015-12-06 12:45 - 2015-12-06 12:45 - 00386096 ____C (AVAST Software) C:\Windows\system32\aswBoot.exe
2015-12-06 12:45 - 2015-12-06 12:45 - 00043112 ____C (AVAST Software) C:\Windows\avastSS.scr
2015-12-04 14:37 - 2015-12-04 14:37 - 00000000 ___DC C:\Windows\System32\Tasks\AVAST Software
2015-12-04 14:37 - 2015-12-04 14:37 - 00000000 ___DC C:\Program Files\Common Files\AV
2015-12-03 14:59 - 2015-12-03 14:59 - 00000000 ___DC C:\Users\honza\AppData\Local\CEF
==================== One Month Modified files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2016-01-02 21:53 - 2009-07-14 04:20 - 00000000 ___DC C:\Windows
2016-01-02 21:44 - 2013-10-12 07:20 - 00000952 ____C C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2016-01-02 21:19 - 2015-10-15 09:51 - 00000958 ____C C:\Windows\Tasks\Adobe Flash Player PPAPI Notifier.job
2016-01-02 19:09 - 2009-07-14 05:45 - 00015984 ___HC C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2016-01-02 19:09 - 2009-07-14 05:45 - 00015984 ___HC C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2016-01-02 19:06 - 2010-10-14 21:36 - 00667902 ____C C:\Windows\system32\perfh005.dat
2016-01-02 19:06 - 2010-10-14 21:36 - 00141048 ____C C:\Windows\system32\perfc005.dat
2016-01-02 19:06 - 2009-07-14 06:13 - 01581054 ____C C:\Windows\system32\PerfStringBackup.INI
2016-01-02 19:06 - 2009-07-14 04:20 - 00000000 ___DC C:\Windows\inf
2016-01-02 19:05 - 2013-01-22 14:16 - 00000000 __RDC C:\Users\honza\Desktop\Nová složka
2016-01-02 19:02 - 2013-10-12 07:20 - 00000948 ____C C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2016-01-02 19:02 - 2009-07-14 06:08 - 00000006 ___HC C:\Windows\Tasks\SA.DAT
2016-01-02 19:01 - 2013-03-15 03:04 - 00000000 ___DC C:\Program Files\Microsoft Silverlight
2016-01-02 19:01 - 2013-03-15 03:04 - 00000000 ___DC C:\Program Files (x86)\Microsoft Silverlight
2016-01-02 17:26 - 2013-05-30 23:42 - 00000000 ___DC C:\Users\honza\AppData\Roaming\uTorrent
2016-01-02 14:36 - 2013-01-30 15:22 - 00000000 ___DC C:\Users\honza\AppData\Roaming\vlc
2016-01-02 13:22 - 2013-03-15 03:06 - 00000000 ___DC C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Silverlight
2016-01-02 13:21 - 2013-07-15 02:01 - 00000000 ___DC C:\Windows\system32\MRT
2016-01-02 13:13 - 2013-03-02 03:37 - 00796864 ____C (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2016-01-02 13:13 - 2012-01-25 11:21 - 00142528 ____C (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2016-01-02 13:10 - 2011-10-25 00:52 - 140158008 ____C (Microsoft Corporation) C:\Windows\system32\MRT.exe
2015-12-27 14:09 - 2013-11-13 00:19 - 00004182 ____C C:\Windows\System32\Tasks\avast! Emergency Update
2015-12-21 18:08 - 2015-05-12 13:00 - 00000000 ___DC C:\Users\honza\AppData\Local\CrashDumps
2015-12-19 08:55 - 2013-11-27 14:16 - 00451040 ____C (AVAST Software) C:\Windows\system32\Drivers\aswsp.sys
2015-12-19 08:55 - 2013-11-27 14:16 - 00097648 ____C (AVAST Software) C:\Windows\system32\Drivers\aswmonflt.sys
2015-12-14 20:46 - 2015-07-07 02:36 - 00000000 ___DC C:\Users\honza\AppData\Roaming\Media Player Classic
2015-12-07 14:00 - 2015-09-23 13:10 - 00000000 ___DC C:\ProgramData\Package Cache
2015-12-06 19:35 - 2015-01-27 07:40 - 00000000 ___DC C:\Users\honza\knihovna
2015-12-06 12:45 - 2014-04-26 20:47 - 00028656 ____C (AVAST Software) C:\Windows\system32\Drivers\aswHwid.sys
2015-12-06 12:45 - 2013-12-26 20:56 - 00155304 ____C (AVAST Software) C:\Windows\system32\Drivers\aswStm.sys
2015-12-06 12:45 - 2013-11-27 14:16 - 01055560 ____C (AVAST Software) C:\Windows\system32\Drivers\aswSnx.sys
2015-12-06 12:45 - 2013-11-27 14:16 - 00273784 ____C (AVAST Software) C:\Windows\system32\Drivers\aswVmm.sys
2015-12-06 12:45 - 2013-11-27 14:16 - 00065224 ____C (AVAST Software) C:\Windows\system32\Drivers\aswRvrt.sys
2015-12-06 12:45 - 2013-11-27 14:15 - 00093528 ____C (AVAST Software) C:\Windows\system32\Drivers\aswRdr2.sys
2015-12-06 12:39 - 2011-09-16 23:42 - 00003948 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA
2015-12-06 12:39 - 2011-09-16 23:42 - 00003696 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore
2015-12-04 22:28 - 2012-11-13 15:44 - 00000000 ___DC C:\Hry
2015-12-03 15:06 - 2015-11-01 18:11 - 00002441 ____C C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Acrobat Reader DC.lnk
2015-12-03 14:59 - 2014-07-09 09:59 - 00000000 ___DC C:\Users\honza\AppData\Local\Adobe
==================== Files in the root of some directories =======
2002-08-29 18:33 - 2002-08-29 18:33 - 0319488 ___RC () C:\Users\honza\AppData\Roaming\MafiaSetup.exe
2013-12-12 23:47 - 2013-12-12 23:48 - 0039073 ____C () C:\Users\honza\AppData\Local\Perfmon.PerfmonCfg
2013-11-27 23:06 - 2013-11-27 23:06 - 0007668 ____C () C:\Users\honza\AppData\Local\Resmon.ResmonCfg
2015-06-01 18:25 - 2015-06-01 18:25 - 0000000 ____C () C:\Users\honza\AppData\Local\{2136A391-B028-47DF-A112-8FCA991D85B2}
2013-09-06 22:07 - 2013-09-06 22:07 - 0030621 ____C () C:\ProgramData\1378501603.bdinstall.bin
2013-09-06 22:08 - 2013-09-06 22:08 - 0029600 ____C () C:\ProgramData\1378501699.1000.bin
2013-09-06 22:08 - 2013-09-06 22:08 - 0000798 ____C () C:\ProgramData\1378501699.2376.bin
2013-09-06 22:08 - 2013-09-06 22:08 - 0002052 ____C () C:\ProgramData\1378501699.4508.bin
2013-09-06 22:10 - 2013-09-06 22:10 - 0030489 ____C () C:\ProgramData\1378501837.bdinstall.bin
2013-09-06 22:19 - 2013-09-06 22:19 - 0195664 ____C () C:\ProgramData\1378502170.bdinstall.bin
2013-10-07 09:58 - 2013-10-07 09:58 - 0022988 ____C () C:\ProgramData\1381136314.bdinstall.bin
2013-10-07 10:01 - 2013-10-07 10:01 - 0079615 ____C () C:\ProgramData\1381136320.bdinstall.bin
2013-11-02 13:49 - 2013-11-02 13:49 - 0229590 ____C () C:\ProgramData\1383396454.bdinstall.bin
2013-11-02 13:53 - 2013-11-02 13:53 - 0037592 ____C () C:\ProgramData\1383396818.bdinstall.bin
2013-11-02 14:14 - 2013-11-02 14:14 - 0174510 ____C () C:\ProgramData\1383396823.bdinstall.bin
2013-11-02 14:37 - 2013-11-02 14:37 - 0037842 ____C () C:\ProgramData\1383399436.bdinstall.bin
2013-11-02 14:38 - 2013-11-02 14:38 - 0095257 ____C () C:\ProgramData\1383399441.bdinstall.bin
==================== Bamital & volsnap =================
(There is no automatic fix for files that do not pass verification.)
C:\Windows\system32\winlogon.exe => File is digitally signed
C:\Windows\system32\wininit.exe => File is digitally signed
C:\Windows\SysWOW64\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\system32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\system32\services.exe => File is digitally signed
C:\Windows\system32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\system32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\system32\rpcss.dll => File is digitally signed
C:\Windows\system32\dnsapi.dll => File is digitally signed
C:\Windows\SysWOW64\dnsapi.dll => File is digitally signed
C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed
LastRegBack: 2016-01-02 15:50
==================== End of FRST.txt ============================
Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version:31-12-2015
Ran by honza (administrator) on MARTIN (02-01-2016 21:53:21)
Running from C:\Users\honza\Desktop
Loaded Profiles: honza (Available Profiles: honza & Guest)
Platform: Windows 7 Home Premium (X64) Language: Čeština (Česká republika)
Internet Explorer Version 9 (Default browser: Chrome)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/33 ... scan-tool/
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(AMD) C:\Windows\System32\atiesrxx.exe
(AMD) C:\Windows\System32\atieclxx.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe
(SUPERAntiSpyware.com) C:\Program Files\SUPERAntiSpyware\SASCore64.exe
(Broadcom Corporation.) C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe
(Comodo) C:\Program Files (x86)\Comodo\Dragon\dragon_updater.exe
(Macrovision Corporation) C:\Program Files (x86)\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
(Google Inc.) C:\Program Files (x86)\Google\Update\1.3.29.1\GoogleCrashHandler.exe
(Google Inc.) C:\Program Files (x86)\Google\Update\1.3.29.1\GoogleCrashHandler64.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(ArcSoft, Inc.) C:\Program Files (x86)\ArcSoft\Magic-i Visual Effects 2\uCamMonitor.exe
(Sony Corporation) C:\Program Files\Sony\VAIO Power Management\SPMgr.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastUI.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
==================== Registry (Whitelisted) ===========================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM-x32\...\Run: [AvastUI.exe] => C:\Program Files\AVAST Software\Avast\AvastUI.exe [7021880 2015-12-06] (AVAST Software)
Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation)
HKU\S-1-5-21-866132977-3524765048-2583430549-1000\...\RunOnce: [FlashPlayerUpdate] => C:\Windows\SysWOW64\Macromed\Flash\FlashUtil32_19_0_0_245_pepper.exe [1158856 2015-12-02] (Adobe Systems Incorporated)
HKU\S-1-5-21-866132977-3524765048-2583430549-1000\...\MountPoints2: {e162d644-151a-11e5-b93d-ec55f9e929bb} - E:\setup.exe
HKU\S-1-5-21-866132977-3524765048-2583430549-1000\...\MountPoints2: {e162d647-151a-11e5-b93d-ec55f9e929bb} - G:\m.exe
HKU\S-1-5-21-866132977-3524765048-2583430549-1000\...\MountPoints2: {e17b9178-a0e5-11e4-a51d-ec55f9e929bb} - J:\HiSuiteDownLoader.exe
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - %SystemRoot%\system32\wpdshserviceobj.dll (Microsoft Corporation)
ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShA64.dll [2015-12-06] (AVAST Software)
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
Tcpip\Parameters: [DhcpNameServer] 192.168.43.1
Tcpip\..\Interfaces\{25559BA7-6EF9-45A1-8A74-5DE0661ACE12}: [DhcpNameServer] 192.168.42.129
Tcpip\..\Interfaces\{A3BBF46B-A159-4BF4-B070-5D52FC44EA02}: [DhcpNameServer] 10.0.0.138
Tcpip\..\Interfaces\{A54718C9-FD98-4D35-9BC5-17E8F314811B}: [DhcpNameServer] 192.168.100.254
Tcpip\..\Interfaces\{D814BF20-A917-41A7-BDAA-43E59F9CD8E7}: [DhcpNameServer] 192.168.42.129
Tcpip\..\Interfaces\{FCCB9CFF-7B76-46F5-A504-F6C1EE5BE0D5}: [DhcpNameServer] 192.168.43.1
Internet Explorer:
==================
HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Local Page =
SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-21-866132977-3524765048-2583430549-1000 -> {012E1000-F331-11DB-8314-0800200C9A66} URL = hxxp://www.google.com/search?q={searchTerms}
BHO: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll [2015-11-18] (AVAST Software)
BHO: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2011-03-28] (Microsoft Corp.)
BHO: No Name -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> No File
BHO-x32: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll [2015-11-18] (AVAST Software)
BHO-x32: Pomocná služba pro přihlášení ke službě Windows Live ID -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2011-03-28] (Microsoft Corp.)
Toolbar: HKLM - No Name - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - No File
Toolbar: HKLM - No Name - {CC1A175A-E45B-41ED-A30C-C9B1D7A0C02F} - No File
FireFox:
========
FF ProfilePath: C:\Users\honza\AppData\Roaming\Mozilla\Firefox\Profiles\wh42cenw.default
FF Homepage: hxxp://www.seznam.cz/
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_20_0_0_267.dll [2016-01-02] ()
FF Plugin: @microsoft.com/GENUINE -> C:\Windows\system32\Wat\npWatWeb.dll [2011-09-19] (Microsoft Corporation)
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.41105.0\npctrl.dll [2015-11-04] ( Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_20_0_0_267.dll [2016-01-02] ()
FF Plugin-x32: @adobe.com/ShockwavePlayer -> C:\Windows\SysWOW64\Adobe\Director\np32dsw_1222172.dll [2015-11-19] (Adobe Systems, Inc.)
FF Plugin-x32: @Google.com/GoogleEarthPlugin -> C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll [2013-10-07] (Google)
FF Plugin-x32: @microsoft.com/GENUINE -> C:\Windows\system32\Wat\npWatWeb.dll [2011-09-19] (Microsoft Corporation)
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\5.1.41105.0\npctrl.dll [2015-11-04] ( Microsoft Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.29.1\npGoogleUpdate3.dll [2015-12-06] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.29.1\npGoogleUpdate3.dll [2015-12-06] (Google Inc.)
FF Plugin-x32: @videolan.org/vlc,version=2.0.5 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2015-04-13] (VideoLAN)
FF Plugin-x32: @videolan.org/vlc,version=2.1.0 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2015-04-13] (VideoLAN)
FF Plugin-x32: @videolan.org/vlc,version=2.1.1 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2015-04-13] (VideoLAN)
FF Plugin-x32: @videolan.org/vlc,version=2.1.2 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2015-04-13] (VideoLAN)
FF Plugin-x32: @videolan.org/vlc,version=2.1.3 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2015-04-13] (VideoLAN)
FF Plugin-x32: @videolan.org/vlc,version=2.1.5 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2015-04-13] (VideoLAN)
FF Plugin-x32: @videolan.org/vlc,version=2.2.1 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2015-04-13] (VideoLAN)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll [2015-09-30] (Adobe Systems Inc.)
FF Plugin HKU\S-1-5-21-866132977-3524765048-2583430549-1000: @tools.google.com/Google Update;version=3 -> C:\Users\honza\AppData\Local\Google\Update\1.3.22.3\npGoogleUpdate3.dll [2013-12-07] (Google Inc.)
FF Plugin HKU\S-1-5-21-866132977-3524765048-2583430549-1000: @tools.google.com/Google Update;version=9 -> C:\Users\honza\AppData\Local\Google\Update\1.3.22.3\npGoogleUpdate3.dll [2013-12-07] (Google Inc.)
FF Plugin HKU\S-1-5-21-866132977-3524765048-2583430549-1000: ubisoft.com/uplaypc -> C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\npuplaypc.dll [No File]
FF user.js: detected! => C:\Users\honza\AppData\Roaming\Mozilla\Firefox\Profiles\wh42cenw.default\user.js [2015-12-07]
FF Extension: Money Viking - C:\Users\honza\AppData\Roaming\Mozilla\Firefox\Profiles\wh42cenw.default\Extensions\{8ef52718-ef02-42dc-991a-dd0e9f7bbf20}.xpi [2015-12-06] [not signed]
FF HKLM-x32\...\Firefox\Extensions: [wrc@avast.com] - C:\Program Files\AVAST Software\Avast\WebRep\FF
FF Extension: Avast Online Security - C:\Program Files\AVAST Software\Avast\WebRep\FF [2015-12-06]
FF HKLM-x32\...\Firefox\Extensions: [sp@avast.com] - C:\Program Files\AVAST Software\Avast\SafePrice\FF
FF Extension: Avast SafePrice - C:\Program Files\AVAST Software\Avast\SafePrice\FF [2015-12-06]
Chrome:
=======
CHR HomePage: Default -> hxxp://www.seznam.cz/
CHR Session Restore: Default -> is enabled.
CHR Profile: C:\Users\honza\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (Prezentace Google) - C:\Users\honza\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2015-04-08]
CHR Extension: (Dokumenty Google) - C:\Users\honza\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2015-04-09]
CHR Extension: (Disk Google) - C:\Users\honza\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2015-10-22]
CHR Extension: (YouTube) - C:\Users\honza\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2015-09-24]
CHR Extension: (Vyhledávání Google) - C:\Users\honza\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2015-10-29]
CHR Extension: (Tabulky Google) - C:\Users\honza\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2015-04-08]
CHR Extension: (Dokumenty Google offline) - C:\Users\honza\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2015-11-17]
CHR Extension: (Avast Online Security) - C:\Users\honza\AppData\Local\Google\Chrome\User Data\Default\Extensions\gomekmidlodglbbmalcneegieacbdmki [2015-11-07]
CHR Extension: (Platby Internetového obchodu Chrome) - C:\Users\honza\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2015-07-31]
CHR Extension: (Gmail) - C:\Users\honza\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2015-04-09]
CHR HKLM\...\Chrome\Extension: [flliilndjeohchalpbbcdekjklbdgfkk] - hxxps://clients2.google.com/service/update2/crx
CHR HKLM-x32\...\Chrome\Extension: [flliilndjeohchalpbbcdekjklbdgfkk] - hxxps://clients2.google.com/service/update2/crx
CHR HKLM-x32\...\Chrome\Extension: [gomekmidlodglbbmalcneegieacbdmki] - C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChrome.crx [2015-11-18]
StartMenuInternet: Google Chrome.B25RZPGWCXT6AHLMJWE2AJ4DJU - C:\Users\Guest\AppData\Local\Google\Chrome\Application\chrome.exe
==================== Services (Whitelisted) ========================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R2 !SASCORE; C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE [144152 2013-10-10] (SUPERAntiSpyware.com)
S3 ACDaemon; C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACService.exe [113152 2010-03-18] (ArcSoft Inc.)
R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [226440 2015-12-06] (AVAST Software)
S3 Disc Soft Lite Bus Service; C:\Program Files\DAEMON Tools Lite\DiscSoftBusService.exe [1272560 2015-05-21] (Disc Soft Ltd)
R2 DragonUpdater; C:\Program Files (x86)\Comodo\Dragon\dragon_updater.exe [2056376 2015-11-20] (Comodo)
R2 IDriverT; C:\Program Files (x86)\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe [69632 2005-04-03] (Macrovision Corporation) [File not signed]
S2 MBAMService; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe [1133880 2015-06-18] (Malwarebytes Corporation)
S3 ssinstall; C:\Windows\SysWOW64\ssins.exe [2317848 2013-03-03] ()
R2 uCamMonitor; C:\Program Files (x86)\ArcSoft\Magic-i Visual Effects 2\uCamMonitor.exe [104960 2008-09-18] (ArcSoft, Inc.)
S3 VCFw; C:\Program Files (x86)\Common Files\Sony Shared\VAIO Content Folder Watcher\VCFw.exe [851824 2010-06-17] (Sony Corporation)
S3 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2009-07-14] (Microsoft Corporation)
S3 AvastVBoxSvc; C:\Program Files\AVAST Software\Avast\ng\vbox\AvastVBoxSVC.exe [X]
===================== Drivers (Whitelisted) ==========================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R3 ArcSoftKsUFilter; C:\Windows\System32\DRIVERS\ArcSoftKsUFilter.sys [19968 2009-05-26] (ArcSoft, Inc.)
R2 aswHwid; C:\Windows\system32\drivers\aswHwid.sys [28656 2015-12-06] (AVAST Software)
R2 aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [97648 2015-12-19] (AVAST Software)
R1 aswRdr; C:\Windows\system32\drivers\aswRdr2.sys [93528 2015-12-06] (AVAST Software)
R0 aswRvrt; C:\Windows\System32\Drivers\aswRvrt.sys [65224 2015-12-06] (AVAST Software)
R1 aswSnx; C:\Windows\system32\drivers\aswSnx.sys [1055560 2015-12-06] (AVAST Software)
R1 aswSP; C:\Windows\system32\drivers\aswSP.sys [451040 2015-12-19] (AVAST Software)
S2 aswStm; C:\Windows\system32\drivers\aswStm.sys [155304 2015-12-06] (AVAST Software)
R0 aswVmm; C:\Windows\System32\Drivers\aswVmm.sys [273784 2015-12-06] (AVAST Software)
R3 dtlitescsibus; C:\Windows\System32\DRIVERS\dtlitescsibus.sys [30264 2015-06-17] (Disc Soft Ltd)
S3 ebdrv; C:\Windows\system32\drivers\evbda.sys [3286016 2009-06-10] (Broadcom Corporation)
S3 igfx; C:\Windows\System32\DRIVERS\igdkmd64.sys [10326784 2010-06-24] (Intel Corporation) [File not signed]
S3 IntcDAud; C:\Windows\System32\DRIVERS\IntcDAud.sys [271872 2010-06-24] (Intel(R) Corporation) [File not signed]
S3 massfilter_hs; C:\Windows\System32\drivers\massfilter_hs.sys [18456 2011-03-07] (HandSet Incorporated)
R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25816 2015-06-18] (Malwarebytes Corporation)
S3 MBAMWebAccessControl; C:\Windows\system32\drivers\mwac.sys [63704 2015-06-18] (Malwarebytes Corporation)
R1 SASDIFSV; C:\Program Files\SUPERAntiSpyware\SASDIFSV64.SYS [14928 2011-07-22] (SUPERAdBlocker.com and SUPERAntiSpyware.com)
R1 SASKUTIL; C:\Program Files\SUPERAntiSpyware\SASKUTIL64.SYS [12368 2011-07-12] (SUPERAdBlocker.com and SUPERAntiSpyware.com)
S4 sfdrv01; C:\Windows\System32\drivers\sfdrv01.sys [69120 2006-03-26] (Protection Technology (StarForce)) [File not signed]
S4 sfhlp02; C:\Windows\System32\drivers\sfhlp02.sys [7168 2006-03-13] (Protection Technology (StarForce)) [File not signed]
S3 ew_hwusbdev; system32\DRIVERS\ew_hwusbdev.sys [X]
S3 ew_usbenumfilter; system32\DRIVERS\ew_usbenumfilter.sys [X]
S3 Huawei; system32\DRIVERS\ewdcsc.sys [X]
S3 huawei_cdcacm; system32\DRIVERS\ew_jucdcacm.sys [X]
S3 huawei_enumerator; system32\DRIVERS\ew_jubusenum.sys [X]
S3 huawei_ext_ctrl; system32\DRIVERS\ew_juextctrl.sys [X]
S3 huawei_wwanecm; system32\DRIVERS\ew_juwwanecm.sys [X]
S3 hwdatacard; system32\DRIVERS\ewusbmdm.sys [X]
S3 NLNdisMP; system32\DRIVERS\nlndis.sys [X]
S3 NLNdisPT; system32\DRIVERS\nlndis.sys [X]
U4 VBoxAswDrv; \??\C:\Program Files\AVAST Software\Avast\ng\vbox\VBoxAswDrv.sys [X]
S3 vserial; System32\DRIVERS\vserial.sys [X]
S3 WinRing0_1_2_0; \??\C:\Program Files (x86)\BatteryCare\WinRing0x64.sys [X]
==================== NetSvcs (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
==================== One Month Created files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2016-01-02 21:53 - 2016-01-02 21:53 - 00016928 ____C C:\Users\honza\Desktop\FRST.txt
2016-01-02 21:53 - 2016-01-02 21:53 - 00000000 ___DC C:\FRST
2016-01-02 21:48 - 2016-01-02 21:48 - 02370560 ____C (Farbar) C:\Users\honza\Desktop\FRST64.exe
2016-01-02 15:32 - 2016-01-02 15:35 - 00000000 ___DC C:\Users\honza\Downloads\série 5 (7.ep)
2016-01-02 15:21 - 2016-01-02 16:09 - 00000000 ___DC C:\Users\honza\Downloads\Ancient Discoveries serie 1
2016-01-02 14:35 - 2016-01-02 14:36 - 00000000 ___DC C:\Users\honza\Downloads\Na ostrově s Bearem Gryllsem 1. Séria
2016-01-02 13:27 - 2016-01-02 13:29 - 00000000 ___DC C:\Users\honza\Downloads\The Martian 2015 720p BluRay x264-88keyz
2016-01-02 13:12 - 2016-01-02 21:32 - 00000914 ____C C:\Windows\Tasks\Adobe Flash Player Updater.job
2016-01-02 13:12 - 2016-01-02 13:13 - 00003852 ____C C:\Windows\System32\Tasks\Adobe Flash Player Updater
2015-12-28 14:46 - 2015-12-28 14:46 - 00121680 ____C C:\Users\honza\AppData\Local\GDIPFONTCACHEV1.DAT
2015-12-17 12:44 - 2015-12-17 12:45 - 00461784 ____C C:\Windows\system32\FNTCACHE.DAT
2015-12-07 14:04 - 2015-12-07 14:04 - 00000000 ___DC C:\Users\honza\AppData\Roaming\MAGIX
2015-12-07 14:04 - 2015-12-07 14:04 - 00000000 ___DC C:\ProgramData\MAGIX
2015-12-07 14:00 - 2015-12-07 14:05 - 00000000 ___DC C:\ProgramData\simplitec
2015-12-07 14:00 - 2015-05-06 16:54 - 00120200 ____C () C:\Windows\SysWOW64\DLLDEV32i.dll
2015-12-07 13:47 - 2015-12-07 13:47 - 00000000 ___DC C:\ProgramData\12bfc3a0-7ee7-1
2015-12-07 13:47 - 2015-12-07 13:47 - 00000000 ___DC C:\ProgramData\12bfc3a0-6997-0
2015-12-06 12:45 - 2015-12-06 12:45 - 00386096 ____C (AVAST Software) C:\Windows\system32\aswBoot.exe
2015-12-06 12:45 - 2015-12-06 12:45 - 00043112 ____C (AVAST Software) C:\Windows\avastSS.scr
2015-12-04 14:37 - 2015-12-04 14:37 - 00000000 ___DC C:\Windows\System32\Tasks\AVAST Software
2015-12-04 14:37 - 2015-12-04 14:37 - 00000000 ___DC C:\Program Files\Common Files\AV
2015-12-03 14:59 - 2015-12-03 14:59 - 00000000 ___DC C:\Users\honza\AppData\Local\CEF
==================== One Month Modified files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2016-01-02 21:53 - 2009-07-14 04:20 - 00000000 ___DC C:\Windows
2016-01-02 21:44 - 2013-10-12 07:20 - 00000952 ____C C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2016-01-02 21:19 - 2015-10-15 09:51 - 00000958 ____C C:\Windows\Tasks\Adobe Flash Player PPAPI Notifier.job
2016-01-02 19:09 - 2009-07-14 05:45 - 00015984 ___HC C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2016-01-02 19:09 - 2009-07-14 05:45 - 00015984 ___HC C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2016-01-02 19:06 - 2010-10-14 21:36 - 00667902 ____C C:\Windows\system32\perfh005.dat
2016-01-02 19:06 - 2010-10-14 21:36 - 00141048 ____C C:\Windows\system32\perfc005.dat
2016-01-02 19:06 - 2009-07-14 06:13 - 01581054 ____C C:\Windows\system32\PerfStringBackup.INI
2016-01-02 19:06 - 2009-07-14 04:20 - 00000000 ___DC C:\Windows\inf
2016-01-02 19:05 - 2013-01-22 14:16 - 00000000 __RDC C:\Users\honza\Desktop\Nová složka
2016-01-02 19:02 - 2013-10-12 07:20 - 00000948 ____C C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2016-01-02 19:02 - 2009-07-14 06:08 - 00000006 ___HC C:\Windows\Tasks\SA.DAT
2016-01-02 19:01 - 2013-03-15 03:04 - 00000000 ___DC C:\Program Files\Microsoft Silverlight
2016-01-02 19:01 - 2013-03-15 03:04 - 00000000 ___DC C:\Program Files (x86)\Microsoft Silverlight
2016-01-02 17:26 - 2013-05-30 23:42 - 00000000 ___DC C:\Users\honza\AppData\Roaming\uTorrent
2016-01-02 14:36 - 2013-01-30 15:22 - 00000000 ___DC C:\Users\honza\AppData\Roaming\vlc
2016-01-02 13:22 - 2013-03-15 03:06 - 00000000 ___DC C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Silverlight
2016-01-02 13:21 - 2013-07-15 02:01 - 00000000 ___DC C:\Windows\system32\MRT
2016-01-02 13:13 - 2013-03-02 03:37 - 00796864 ____C (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2016-01-02 13:13 - 2012-01-25 11:21 - 00142528 ____C (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2016-01-02 13:10 - 2011-10-25 00:52 - 140158008 ____C (Microsoft Corporation) C:\Windows\system32\MRT.exe
2015-12-27 14:09 - 2013-11-13 00:19 - 00004182 ____C C:\Windows\System32\Tasks\avast! Emergency Update
2015-12-21 18:08 - 2015-05-12 13:00 - 00000000 ___DC C:\Users\honza\AppData\Local\CrashDumps
2015-12-19 08:55 - 2013-11-27 14:16 - 00451040 ____C (AVAST Software) C:\Windows\system32\Drivers\aswsp.sys
2015-12-19 08:55 - 2013-11-27 14:16 - 00097648 ____C (AVAST Software) C:\Windows\system32\Drivers\aswmonflt.sys
2015-12-14 20:46 - 2015-07-07 02:36 - 00000000 ___DC C:\Users\honza\AppData\Roaming\Media Player Classic
2015-12-07 14:00 - 2015-09-23 13:10 - 00000000 ___DC C:\ProgramData\Package Cache
2015-12-06 19:35 - 2015-01-27 07:40 - 00000000 ___DC C:\Users\honza\knihovna
2015-12-06 12:45 - 2014-04-26 20:47 - 00028656 ____C (AVAST Software) C:\Windows\system32\Drivers\aswHwid.sys
2015-12-06 12:45 - 2013-12-26 20:56 - 00155304 ____C (AVAST Software) C:\Windows\system32\Drivers\aswStm.sys
2015-12-06 12:45 - 2013-11-27 14:16 - 01055560 ____C (AVAST Software) C:\Windows\system32\Drivers\aswSnx.sys
2015-12-06 12:45 - 2013-11-27 14:16 - 00273784 ____C (AVAST Software) C:\Windows\system32\Drivers\aswVmm.sys
2015-12-06 12:45 - 2013-11-27 14:16 - 00065224 ____C (AVAST Software) C:\Windows\system32\Drivers\aswRvrt.sys
2015-12-06 12:45 - 2013-11-27 14:15 - 00093528 ____C (AVAST Software) C:\Windows\system32\Drivers\aswRdr2.sys
2015-12-06 12:39 - 2011-09-16 23:42 - 00003948 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA
2015-12-06 12:39 - 2011-09-16 23:42 - 00003696 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore
2015-12-04 22:28 - 2012-11-13 15:44 - 00000000 ___DC C:\Hry
2015-12-03 15:06 - 2015-11-01 18:11 - 00002441 ____C C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Acrobat Reader DC.lnk
2015-12-03 14:59 - 2014-07-09 09:59 - 00000000 ___DC C:\Users\honza\AppData\Local\Adobe
==================== Files in the root of some directories =======
2002-08-29 18:33 - 2002-08-29 18:33 - 0319488 ___RC () C:\Users\honza\AppData\Roaming\MafiaSetup.exe
2013-12-12 23:47 - 2013-12-12 23:48 - 0039073 ____C () C:\Users\honza\AppData\Local\Perfmon.PerfmonCfg
2013-11-27 23:06 - 2013-11-27 23:06 - 0007668 ____C () C:\Users\honza\AppData\Local\Resmon.ResmonCfg
2015-06-01 18:25 - 2015-06-01 18:25 - 0000000 ____C () C:\Users\honza\AppData\Local\{2136A391-B028-47DF-A112-8FCA991D85B2}
2013-09-06 22:07 - 2013-09-06 22:07 - 0030621 ____C () C:\ProgramData\1378501603.bdinstall.bin
2013-09-06 22:08 - 2013-09-06 22:08 - 0029600 ____C () C:\ProgramData\1378501699.1000.bin
2013-09-06 22:08 - 2013-09-06 22:08 - 0000798 ____C () C:\ProgramData\1378501699.2376.bin
2013-09-06 22:08 - 2013-09-06 22:08 - 0002052 ____C () C:\ProgramData\1378501699.4508.bin
2013-09-06 22:10 - 2013-09-06 22:10 - 0030489 ____C () C:\ProgramData\1378501837.bdinstall.bin
2013-09-06 22:19 - 2013-09-06 22:19 - 0195664 ____C () C:\ProgramData\1378502170.bdinstall.bin
2013-10-07 09:58 - 2013-10-07 09:58 - 0022988 ____C () C:\ProgramData\1381136314.bdinstall.bin
2013-10-07 10:01 - 2013-10-07 10:01 - 0079615 ____C () C:\ProgramData\1381136320.bdinstall.bin
2013-11-02 13:49 - 2013-11-02 13:49 - 0229590 ____C () C:\ProgramData\1383396454.bdinstall.bin
2013-11-02 13:53 - 2013-11-02 13:53 - 0037592 ____C () C:\ProgramData\1383396818.bdinstall.bin
2013-11-02 14:14 - 2013-11-02 14:14 - 0174510 ____C () C:\ProgramData\1383396823.bdinstall.bin
2013-11-02 14:37 - 2013-11-02 14:37 - 0037842 ____C () C:\ProgramData\1383399436.bdinstall.bin
2013-11-02 14:38 - 2013-11-02 14:38 - 0095257 ____C () C:\ProgramData\1383399441.bdinstall.bin
==================== Bamital & volsnap =================
(There is no automatic fix for files that do not pass verification.)
C:\Windows\system32\winlogon.exe => File is digitally signed
C:\Windows\system32\wininit.exe => File is digitally signed
C:\Windows\SysWOW64\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\system32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\system32\services.exe => File is digitally signed
C:\Windows\system32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\system32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\system32\rpcss.dll => File is digitally signed
C:\Windows\system32\dnsapi.dll => File is digitally signed
C:\Windows\SysWOW64\dnsapi.dll => File is digitally signed
C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed
LastRegBack: 2016-01-02 15:50
==================== End of FRST.txt ============================