prosím o překontrolování logu
Napsal: 02 led 2016 23:12
Zdravim,prosím,o překontrolování mého logu na notebooku Acer s Windows 7 díky.
Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version:31-12-2015
Ran by Paja (administrator) on PAJA-NOTEBOOK (02-01-2016 22:49:23)
Running from D:\Stažené soubory
Loaded Profiles: Paja (Available Profiles: Paja)
Platform: Microsoft Windows 7 Home Premium Service Pack 1 (X86) Language: Čeština (Česká republika)
Internet Explorer Version 11 (Default browser: FF)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/33 ... scan-tool/
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(AVAST Software) C:\Nainstalovano\Avast\AvastSvc.exe
(Apple Inc.) C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(CyberLink) C:\Nainstalovano\Power DVD 13\PowerDVD13\Kernel\DMS\CLMSMonitorServicePDVD13.exe
(CyberLink) C:\Nainstalovano\Power DVD 13\PowerDVD13\Kernel\DMS\CLMSServerPDVD13.exe
(Ellora Assets Corp.) C:\Nainstalovano\Freemake\CaptureLib\CaptureLibService.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NetService\NvNetworkService.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
() C:\Nainstalovano\reaConverter 7 Standard\rc_service.exe
() C:\Nainstalovano\ProShow\scsiaccess.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
(SlimWare Utilities, Inc.) C:\Program Files\SlimDrivers\SlimDrivers.exe
(AVAST Software) C:\Nainstalovano\Avast\AvastUI.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe
(CyberLink Corp.) C:\Nainstalovano\Power DVD 13\PowerDVD13\PowerDVD13Agent.exe
(Microsoft Corporation) C:\Nainstalovano\Microsoft Office Enterprise 2007\Office12\GrooveMonitor.exe
(NEC Electronics Corporation) C:\Program Files\Western Digital\USB 3.0 Host Controller Driver\Application\nusb3mon.exe
(PowerISO Computing, Inc.) C:\Nainstalovano\PowerISO\PWRISOVM.EXE
() C:\Program Files\Common Files\Freemake Shared\ProductUpdater\ProductUpdater.exe
(iSkySoft) C:\Program Files\Common Files\iSkysoft\iSkysoft Helper Compact\ISHelper.exe
(Apple Inc.) C:\Nainstalovano\Itunes\iTunesHelper.exe
(Microsoft Corporation) C:\Program Files\Windows Sidebar\sidebar.exe
(ZONER software) C:\Nainstalovano\Photo Studio 17\Program32\ZPSTray.exe
(McAfee, Inc.) C:\Program Files\McAfee Security Scan\3.8.150\SSScheduler.exe
() C:\Users\Paja\AppData\Roaming\Seznam.cz\bin\szndesktop.exe
(Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe
(Microsoft Corporation) C:\Windows\System32\GWX\GWX.exe
(Microsoft Corporation) C:\Windows\System32\wbem\unsecapp.exe
(Mozilla Corporation) C:\Nainstalovano\Mozilla Firefox\firefox.exe
==================== Registry (Whitelisted) ===========================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [AvastUI.exe] => C:\Nainstalovano\Avast\AvastUI.exe [7021880 2015-12-18] (AVAST Software)
HKLM\...\Run: [seznam-listicka-distribuce] => C:\Program Files\Seznam.cz\distribution\szninstall.exe [1062472 2013-05-16] ()
HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe [12021464 2000-01-01] (Realtek Semiconductor)
HKLM\...\Run: [PowerDVD13Agent] => C:\Nainstalovano\Power DVD 13\PowerDVD13\PowerDVD13Agent.exe [517144 2013-10-23] (CyberLink Corp.)
HKLM\...\Run: [NeroFilterCheck] => C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe [155648 2006-01-12] (Nero AG)
HKLM\...\Run: [GrooveMonitor] => C:\Nainstalovano\Microsoft Office Enterprise 2007\Office12\GrooveMonitor.exe [31016 2006-10-26] (Microsoft Corporation)
HKLM\...\Run: [NUSB3MON] => C:\Program Files\Western Digital\USB 3.0 Host Controller Driver\Application\nusb3mon.exe [106496 2009-11-20] (NEC Electronics Corporation)
HKLM\...\Run: [PWRISOVM.EXE] => C:\Nainstalovano\PowerISO\PWRISOVM.EXE [200704 2006-12-25] (PowerISO Computing, Inc.)
HKLM\...\Run: [ProductUpdater] => C:\Program Files\Common Files\Freemake Shared\ProductUpdater\ProductUpdater.exe [62464 2015-06-18] ()
HKLM\...\Run: [ChicoSys] => C:\Windows\system32\cc32\webtmr.exe
HKLM\...\Run: [iSkysoft Helper Compact.exe] => C:\Program Files\Common Files\iSkysoft\iSkysoft Helper Compact\ISHelper.exe [2066432 2014-10-31] (iSkySoft)
HKLM\...\Run: [DelaypluginInstall] => C:\ProgramData\iSkysoft\Video Converter Ultimate\DelayPluginI.exe [1960248 2015-10-29] ()
HKLM\...\Run: [iTunesHelper] => C:\Nainstalovano\Itunes\iTunesHelper.exe [157456 2015-10-16] (Apple Inc.)
HKLM\Software\Policies\Microsoft\Windows NT\SystemRestore: [DisableSR/DisableConfig] <===== ATTENTION
HKU\S-1-5-21-203695958-539750940-1501531493-1000\...\Run: [DAEMON Tools Lite] => C:\Nainstalovano\DAEMON Tools Lite\DTLite.exe [3696912 2014-03-04] (Disc Soft Ltd)
HKU\S-1-5-21-203695958-539750940-1501531493-1000\...\Run: [cz.seznam.software.autoupdate] => C:\Users\Paja\AppData\Roaming\Seznam.cz\szninstall.exe [1062472 2013-05-16] ()
HKU\S-1-5-21-203695958-539750940-1501531493-1000\...\Run: [cz.seznam.software.szndesktop] => C:\Users\Paja\AppData\Roaming\Seznam.cz\bin\wszndesktop.exe [103080 2015-05-26] ()
HKU\S-1-5-21-203695958-539750940-1501531493-1000\...\Run: [PowerDVD13] => C:\Nainstalovano\Power DVD 13\PowerDVD13\PDVDLP.exe [470792 2013-10-23] (CyberLink Corp.)
HKU\S-1-5-21-203695958-539750940-1501531493-1000\...\Run: [Super MP3 Download] => C:\Nainstalovano\SuperMp3Download\SuperMp3Download.exe
HKU\S-1-5-21-203695958-539750940-1501531493-1000\...\Run: [Zoner Photo Studio Autoupdate] => C:\NAINSTALOVANO\PHOTO STUDIO 17\Program32\ZPSTRAY.EXE [563416 2015-07-12] (ZONER software)
HKU\S-1-5-21-203695958-539750940-1501531493-1000\...\Policies\system: [DisableLockWorkstation] 0
HKU\S-1-5-21-203695958-539750940-1501531493-1000\...\Policies\system: [DisableClock] 0
HKU\S-1-5-21-203695958-539750940-1501531493-1000\...\Policies\Explorer: [NoSaveSettings] 0
HKU\S-1-5-21-203695958-539750940-1501531493-1000\...\Policies\Explorer: [NoFind] 0
HKU\S-1-5-21-203695958-539750940-1501531493-1000\...\Policies\Explorer: [RestrictRun] 0
HKU\S-1-5-21-203695958-539750940-1501531493-1000\...\MountPoints2: {a502a618-d5c3-11e3-85c8-00238b4d4eb9} - I:\Unlock.exe autoplay=true
HKU\S-1-5-21-203695958-539750940-1501531493-1000\...\MountPoints2: {fed0b4e4-c241-11e3-9ac1-00238b4d4eb9} - F:\Unlock.exe autoplay=true
IFEO: [Debugger] logonui.exe
ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Nainstalovano\Avast\ashShell.dll [2015-12-18] (AVAST Software)
ShellIconOverlayIdentifiers: [Groove Explorer Icon Overlay 1 (GFS Unread Stub)] -> {99FD978C-D287-4F50-827F-B2C658EDA8E7} => C:\Nainstalovano\Microsoft Office Enterprise 2007\Office12\GrooveShellExtensions.dll [2006-10-26] (Microsoft Corporation)
ShellIconOverlayIdentifiers: [Groove Explorer Icon Overlay 2 (GFS Stub)] -> {AB5C5600-7E6E-4B06-9197-9ECEF74D31CC} => C:\Nainstalovano\Microsoft Office Enterprise 2007\Office12\GrooveShellExtensions.dll [2006-10-26] (Microsoft Corporation)
ShellIconOverlayIdentifiers: [Groove Explorer Icon Overlay 2.5 (GFS Unread Folder)] -> {920E6DB1-9907-4370-B3A0-BAFC03D81399} => C:\Nainstalovano\Microsoft Office Enterprise 2007\Office12\GrooveShellExtensions.dll [2006-10-26] (Microsoft Corporation)
ShellIconOverlayIdentifiers: [Groove Explorer Icon Overlay 3 (GFS Folder)] -> {16F3DD56-1AF5-4347-846D-7C10C4192619} => C:\Nainstalovano\Microsoft Office Enterprise 2007\Office12\GrooveShellExtensions.dll [2006-10-26] (Microsoft Corporation)
ShellIconOverlayIdentifiers: [Groove Explorer Icon Overlay 4 (GFS Unread Mark)] -> {2916C86E-86A6-43FE-8112-43ABE6BF8DCC} => C:\Nainstalovano\Microsoft Office Enterprise 2007\Office12\GrooveShellExtensions.dll [2006-10-26] (Microsoft Corporation)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\McAfee Security Scan Plus.lnk [2014-06-16]
ShortcutTarget: McAfee Security Scan Plus.lnk -> C:\Program Files\McAfee Security Scan\3.8.150\SSScheduler.exe (McAfee, Inc.)
GroupPolicy: Restriction - Chrome <======= ATTENTION
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
ProxyServer: [S-1-5-21-203695958-539750940-1501531493-1000] => 127.0.0.1:8118
AutoConfigURL: [S-1-5-21-203695958-539750940-1501531493-1000] => 127.0.0.1:8118
Winsock: Catalog5 08 C:\Program Files\Bonjour\mdnsNSP.dll [122128 2015-08-12] (Apple Inc.)
Hosts: There are more than one entry in Hosts. See Hosts section of Addition.txt
Tcpip\Parameters: [DhcpNameServer] 192.168.1.1
Tcpip\..\Interfaces\{40DC63AB-CEE4-4DC9-B408-F49CC64F1E51}: [DhcpNameServer] 192.168.1.1
Tcpip\..\Interfaces\{4BC8D7B9-962E-4783-9952-1E606FCB20A9}: [NameServer] 10.1.1.0,10.1.1.100
Internet Explorer:
==================
HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer: Restriction <======= ATTENTION
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.google.com
HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.google.com
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.google.com
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://www.google.com
SearchScopes: HKLM -> {20B9D1AE-AD1A-38B4-87FE-AF278DA9861D} URL = hxxps://gosearch.me/?q={searchTerms}&u=8a2ccd6e0fb051f271b9fdac2c41a2ef&c=DP3221&src=srch&inst=1442925936
SearchScopes: HKU\S-1-5-21-203695958-539750940-1501531493-1000 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://search.seznam.cz/?sourceid=quicksearch_6826&q={searchTerms}
SearchScopes: HKU\S-1-5-21-203695958-539750940-1501531493-1000 -> 1500C81568E2C9D8F17E29C71ECBB74C URL = hxxp://videa.seznam.cz/?q={searchTerms}
SearchScopes: HKU\S-1-5-21-203695958-539750940-1501531493-1000 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://search.seznam.cz/?sourceid=quicksearch_6826&q={searchTerms}
SearchScopes: HKU\S-1-5-21-203695958-539750940-1501531493-1000 -> {20B9D1AE-AD1A-38B4-87FE-AF278DA9861D} URL = hxxps://gosearch.me/?q={searchTerms}&u=8a2ccd6e0fb051f271b9fdac2c41a2ef&c=DP3221&src=srch&inst=1442925936
SearchScopes: HKU\S-1-5-21-203695958-539750940-1501531493-1000 -> {277CAC54-E9ED-4D8D-A5EE-B68C989B0702} URL = hxxp://slovnik.seznam.cz/?q={searchTerms}&lang=cz_en&sourceid=QuickSearch_13415
SearchScopes: HKU\S-1-5-21-203695958-539750940-1501531493-1000 -> {689B78F0-8B45-4ECB-9281-07C3EDCB4AC9} URL = hxxp://encyklopedie.seznam.cz/search?q={searchTerms}&sourceid=QuickSearch_13415
SearchScopes: HKU\S-1-5-21-203695958-539750940-1501531493-1000 -> {8C0F53C9-4A67-405B-A162-47CB1D92A819} URL = hxxp://slovnik.seznam.cz/?q={searchTerms}&lang=en_cz&sourceid=QuickSearch_13415
SearchScopes: HKU\S-1-5-21-203695958-539750940-1501531493-1000 -> {ABE66342-AAA7-446E-A568-33A94614EBF0} URL = hxxp://www.zbozi.cz/?q={searchTerms}&r=campmoz ... arch_13415
SearchScopes: HKU\S-1-5-21-203695958-539750940-1501531493-1000 -> {BC7A8C3E-1862-46C6-AB34-E0AE9DAE2F9F} URL = hxxp://www.novinky.cz/hledej?w={searchTerms}&s ... arch_13415
SearchScopes: HKU\S-1-5-21-203695958-539750940-1501531493-1000 -> {DC0205BF-941D-4EF3-A735-94D96E507A52} URL = hxxp://www.firmy.cz/?q={searchTerms}&sourceid= ... arch_13415
SearchScopes: HKU\S-1-5-21-203695958-539750940-1501531493-1000 -> {E3BF7B2D-C987-462D-9BF9-92F2FCC615DA} URL = hxxp://tv.seznam.cz/hledej?w={searchTerms}&sourceid=QuickSearch_13415
SearchScopes: HKU\S-1-5-21-203695958-539750940-1501531493-1000 -> {EF7216C8-7796-4135-8706-0946085FD933} URL = hxxp://www.mapy.cz/?query={searchTerms}&source ... arch_13415
BHO: No Name -> {0E8A89AD-95D7-40EB-8D9D-083EF7066A01} -> No File
BHO: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Nainstalovano\Microsoft Office Enterprise 2007\Office12\GrooveShellExtensions.dll [2006-10-26] (Microsoft Corporation)
BHO: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Nainstalovano\Avast\aswWebRepIE.dll [2015-12-18] (AVAST Software)
BHO: iSkysoft iMedia Converter Deluxe 5.1.0 -> {AEAF002F-E6D8-4A21-ABD3-2B309B79A6CE} -> C:\ProgramData\iSkysoft\Video Converter Ultimate\WSBrowserAppMgr.dll [2015-10-29] (Wondershare)
BHO: No Name -> {D5FEC983-01DB-414A-9456-AF95AC9ED7B5} -> No File
Toolbar: HKU\S-1-5-21-203695958-539750940-1501531493-1000 -> No Name - {91397D20-1446-11D4-8AF4-0040CA1127B6} - No File
Handler: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Nainstalovano\Microsoft Office Enterprise 2007\Office12\GrooveSystemServices.dll [2006-10-26] (Microsoft Corporation)
Handler: mso-minsb-roaming.16 - {83C25742-A9F7-49FB-9138-434302C88D07} - C:\Program Files\Microsoft Office\root\Office16\MSOSB.DLL No File
Handler: mso-minsb.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files\Microsoft Office\root\Office16\MSOSB.DLL No File
Handler: osf-roaming.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files\Microsoft Office\root\Office16\MSOSB.DLL No File
Handler: osf.16 - {5504BE45-A83B-4808-900A-3A5C36E7F77A} - C:\Program Files\Microsoft Office\root\Office16\MSOSB.DLL No File
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll [2014-05-02] (Skype Technologies)
Handler: WSISVCUchrome - {78A543EB-3A61-4ED3 - No File
StartMenuInternet: IEXPLORE.EXE - C:\Program Files\Internet Explorer\iexplore.exe hxxp://www.piesearch.com/?type=sc&ts=145123009 ... 0e25ff60bc
FireFox:
========
FF ProfilePath: C:\Users\Paja\AppData\Roaming\Mozilla\Firefox\Profiles\3456uct3.default
FF Homepage: hxxps://www.seznam.cz/
FF NetworkProxy: "socks_remote_dns", true
FF NetworkProxy: "type", 4
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF32_20_0_0_267.dll [2015-12-28] ()
FF Plugin: @Apple.com/iTunes,version=1.0 -> C:\Nainstalovano\Itunes\Mozilla Plugins\npitunes.dll [2015-10-08] ()
FF Plugin: @microsoft.com/GENUINE -> disabled [No File]
FF Plugin: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files\Microsoft Office\root\Office16\NPSPWRAP.DLL [No File]
FF Plugin: @photodex.com/PhotodexPresenter -> C:\Program Files\Photodex Presenter\npPxPlay.dll [2014-11-11] ( )
FF Plugin: @tools.google.com/Google Update;version=3 -> C:\Program Files\Google\Update\1.3.29.1\npGoogleUpdate3.dll [2015-12-05] (Google Inc.)
FF Plugin: @tools.google.com/Google Update;version=9 -> C:\Program Files\Google\Update\1.3.29.1\npGoogleUpdate3.dll [2015-12-05] (Google Inc.)
FF Plugin: @videolan.org/vlc,version=2.1.5 -> C:\Nainstalovano\VLC\npvlc.dll [2015-04-13] (VideoLAN)
FF Plugin: @videolan.org/vlc,version=2.2.1 -> C:\Nainstalovano\VLC\npvlc.dll [2015-04-13] (VideoLAN)
FF Plugin: Adobe Reader -> C:\Program Files\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll [2015-09-30] (Adobe Systems Inc.)
FF Extension: Seznam lištička - C:\Users\Paja\AppData\Roaming\Mozilla\Firefox\Profiles\3456uct3.default\Extensions\{ea614400-e918-4741-9a97-7a972ff7c30b} [2015-12-12]
FF HKLM\...\Firefox\Extensions: [wrc@avast.com] - C:\Nainstalovano\Avast\WebRep\FF
FF Extension: Avast Online Security - C:\Nainstalovano\Avast\WebRep\FF [2015-12-18]
FF HKLM\...\Firefox\Extensions: [sp@avast.com] - C:\Nainstalovano\Avast\SafePrice\FF
FF Extension: Avast SafePrice - C:\Nainstalovano\Avast\SafePrice\FF [2015-12-18]
FF HKLM\...\Firefox\Extensions: [ISVCU@iSkysoft.com] - C:\ProgramData\iSkysoft\Video Converter Ultimate\ISVCU@iSkysoft.com
FF Extension: iSkysoft iMedia Converter Deluxe - C:\ProgramData\iSkysoft\Video Converter Ultimate\ISVCU@iSkysoft.com [2015-10-29] [not signed]
FF HKU\S-1-5-21-203695958-539750940-1501531493-1000\...\Firefox\Extensions: [{e4f94d1e-2f53-401e-8885-681602c0ddd8}] - C:\ProgramData\McAfee Security Scan\Extensions\{e4f94d1e-2f53-401e-8885-681602c0ddd8}.xpi => not found
StartMenuInternet: FIREFOX.EXE - C:\Nainstalovano\Mozilla Firefox\firefox.exe hxxp://www.piesearch.com/?type=sc&ts=145123009 ... 0e25ff60bc
Chrome:
=======
CHR HomePage: Default -> hxxp://www.seznam.cz/
CHR StartupUrls: Default -> "hxxps://www.seznam.cz/"
CHR Profile: C:\Users\Paja\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (Dokumenty Google) - C:\Users\Paja\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2015-02-13]
CHR Extension: (Disk Google) - C:\Users\Paja\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2015-10-22]
CHR Extension: (Seznam Lištička - Email) - C:\Users\Paja\AppData\Local\Google\Chrome\User Data\Default\Extensions\bgjpfhpjcgdppjbgnpnjllokbmcdllig [2015-02-17]
CHR Extension: (Seznam Lištička - Slovník) - C:\Users\Paja\AppData\Local\Google\Chrome\User Data\Default\Extensions\blmojkbhnkkphngknkmgccmlenfaelkd [2014-04-11]
CHR Extension: (YouTube) - C:\Users\Paja\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2015-09-25]
CHR Extension: (Vyhledávání Google) - C:\Users\Paja\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2015-11-03]
CHR Extension: (Dokumenty Google offline) - C:\Users\Paja\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2015-11-21]
CHR Extension: (Avast Online Security) - C:\Users\Paja\AppData\Local\Google\Chrome\User Data\Default\Extensions\gomekmidlodglbbmalcneegieacbdmki [2015-11-03]
CHR Extension: (Platby Internetového obchodu Chrome) - C:\Users\Paja\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2015-08-04]
CHR Extension: (Seznam Lištička - Rychlá volba) - C:\Users\Paja\AppData\Local\Google\Chrome\User Data\Default\Extensions\olfeabkoenfaoljndfecamgilllcpiak [2015-11-03]
CHR Extension: (Gmail) - C:\Users\Paja\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2015-04-08]
CHR HKLM\...\Chrome\Extension: [bopakagnckmlgajfccecajhnimjiiedh] - hxxp://clients2.google.com/service/update2/crx
CHR HKLM\...\Chrome\Extension: [gomekmidlodglbbmalcneegieacbdmki] - C:\Nainstalovano\Avast\WebRep\Chrome\aswWebRepChrome.crx [2015-12-18]
StartMenuInternet: Google Chrome - C:\Program Files\Google\Chrome\Application\chrome.exe hxxp://www.piesearch.com/?type=sc&ts=145123009 ... 0e25ff60bc
Opera:
=======
OPR StartupUrls: "hxxp://www.seznam.cz/?clid=6826"
StartMenuInternet: (HKLM) OperaStable - C:\Nainstalovano\Opera\Launcher.exe hxxp://www.piesearch.com/?type=sc&ts=145123009 ... 0e25ff60bc
==================== Services (Whitelisted) ========================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R3 AeLookupSvc; C:\Windows\System32\aelupsvc.dll [62464 2015-03-04] (Microsoft Corporation) [File not signed]
S3 AppIDSvc; C:\Windows\System32\appidsvc.dll [27648 2015-02-03] (Microsoft Corporation) [File not signed]
S3 Appinfo; C:\Windows\System32\appinfo.dll [47104 2015-06-15] (Microsoft Corporation) [File not signed]
R2 AudioEndpointBuilder; C:\Windows\System32\Audiosrv.dll [475136 2015-02-03] (Microsoft Corporation) [File not signed]
R2 Audiosrv; C:\Windows\System32\Audiosrv.dll [475136 2015-02-03] (Microsoft Corporation) [File not signed]
R2 avast! Antivirus; C:\Nainstalovano\Avast\AvastSvc.exe [226440 2015-12-18] (AVAST Software)
R2 CryptSvc; C:\Windows\system32\cryptsvc.dll [143872 2015-04-27] (Microsoft Corporation) [File not signed]
R2 CyberLink PowerDVD 13 Media Server Monitor Service; C:\Nainstalovano\Power DVD 13\PowerDVD13\Kernel\DMS\CLMSMonitorServicePDVD13.exe [77576 2013-10-23] (CyberLink)
R2 CyberLink PowerDVD 13 Media Server Service; C:\Nainstalovano\Power DVD 13\PowerDVD13\Kernel\DMS\CLMSServerPDVD13.exe [327432 2013-10-23] (CyberLink)
R2 DiagTrack; C:\Windows\system32\diagtrack.dll [853504 2015-05-25] (Microsoft Corporation) [File not signed]
S3 EFS; C:\Windows\System32\lsass.exe [22528 2015-07-01] (Microsoft Corporation) [File not signed]
R2 FontCache; C:\Windows\system32\FntCache.dll [909312 2015-04-20] (Microsoft Corporation) [File not signed]
R2 FreemakeVideoCapture; C:\Nainstalovano\Freemake\CaptureLib\CaptureLibService.exe [9216 2014-04-17] (Ellora Assets Corp.) [File not signed]
S3 IEEtwCollectorService; C:\Windows\system32\IEEtwCollector.exe [102912 2015-06-19] (Microsoft Corporation) [File not signed]
R3 KeyIso; C:\Windows\system32\lsass.exe [22528 2015-07-01] (Microsoft Corporation) [File not signed]
S3 Microsoft Office Groove Audit Service; C:\Nainstalovano\Microsoft Office Enterprise 2007\Office12\GrooveAuditService.exe [65824 2006-10-26] (Microsoft Corporation)
S3 msiserver; C:\Windows\System32\msiexec.exe [73216 2015-06-15] (Microsoft Corporation) [File not signed]
S3 NBService; C:\Nainstalovano\Nero 7\Nero BackItUp\NBService.exe [774144 2006-11-10] (Nero AG) [File not signed]
S3 Netlogon; C:\Windows\system32\lsass.exe [22528 2015-07-01] (Microsoft Corporation) [File not signed]
R2 NlaSvc; C:\Windows\System32\nlasvc.dll [242688 2014-12-06] (Microsoft Corporation) [File not signed]
R2 NvNetworkService; C:\Program Files\NVIDIA Corporation\NetService\NvNetworkService.exe [1593632 2014-02-05] (NVIDIA Corporation)
R2 NvStreamSvc; C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe [15904544 2014-02-05] (NVIDIA Corporation)
R3 PcaSvc; C:\Windows\System32\pcasvc.dll [157184 2015-02-03] (Microsoft Corporation) [File not signed]
R2 ProfSvc; C:\Windows\system32\profsvc.dll [164864 2014-12-19] (Microsoft Corporation) [File not signed]
S3 ProtectedStorage; C:\Windows\system32\lsass.exe [22528 2015-07-01] (Microsoft Corporation) [File not signed]
R2 reaConverter_service; C:\Nainstalovano\reaConverter 7 Standard\rc_service.exe [2129408 2015-06-19] () [File not signed]
R2 SamSs; C:\Windows\system32\lsass.exe [22528 2015-07-01] (Microsoft Corporation) [File not signed]
R2 ScsiAccess; C:\Nainstalovano\ProShow\ScsiAccess.exe [186760 2014-11-11] ()
S3 TermService; C:\Windows\System32\termsrv.dll [523776 2014-10-14] (Microsoft Corporation) [File not signed]
S3 VaultSvc; C:\Windows\system32\lsass.exe [22528 2015-07-01] (Microsoft Corporation) [File not signed]
R3 WdiServiceHost; C:\Windows\system32\wdi.dll [76800 2015-01-09] (Microsoft Corporation) [File not signed]
R3 WdiSystemHost; C:\Windows\system32\wdi.dll [76800 2015-01-09] (Microsoft Corporation) [File not signed]
R2 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [680960 2013-05-27] (Microsoft Corporation)
S3 WinRM; C:\Windows\system32\WsmSvc.dll [1177088 2014-10-03] (Microsoft Corporation) [File not signed]
R2 wuauserv; C:\Windows\system32\wuaueng.dll [2057216 2015-07-09] (Microsoft Corporation) [File not signed]
U4 AvastVBoxSvc; "C:\Nainstalovano\Avast\ng\vbox\AvastVBoxSVC.exe" [X]
S2 EvtEng; C:\Program Files\Intel\WiFi\bin\EvtEng.exe [X]
S2 MustangService_2015_10_10; C:\ProgramData\TempMoudleSet\MustangSer2728.exe [X]
S3 MyWiFiDHCPDNS; C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe [X]
S2 RegSrvc; C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe [X]
===================== Drivers (Whitelisted) ==========================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
S3 AMPPAL; C:\Windows\System32\DRIVERS\AMPPAL.sys [243712 2011-08-08] (Windows (R) Win 7 DDK provider)
S3 AppID; C:\Windows\system32\drivers\appid.sys [50176 2015-02-03] (Microsoft Corporation) [File not signed]
R2 aswHwid; C:\Windows\system32\drivers\aswHwid.sys [24016 2015-12-18] (AVAST Software)
R2 aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [81168 2015-12-18] (AVAST Software)
R1 aswRdr; C:\Windows\system32\drivers\aswRdr2.sys [81728 2015-12-18] (AVAST Software)
R0 aswRvrt; C:\Windows\system32\Drivers\aswRvrt.sys [49776 2015-12-18] (AVAST Software)
R1 aswSnx; C:\Windows\system32\drivers\aswSnx.sys [794952 2015-12-18] (AVAST Software)
R1 aswSP; C:\Windows\system32\drivers\aswSP.sys [436360 2015-12-18] (AVAST Software)
R2 aswStm; C:\Windows\system32\drivers\aswStm.sys [117712 2015-12-18] (AVAST Software)
R0 aswVmm; C:\Windows\system32\Drivers\aswVmm.sys [209432 2015-12-18] (AVAST Software)
R1 dtsoftbus01; C:\Windows\System32\DRIVERS\dtsoftbus01.sys [243128 2014-04-11] (Disc Soft Ltd)
R3 HTTP; C:\Windows\System32\drivers\HTTP.sys [514560 2015-02-25] (Microsoft Corporation) [File not signed]
R3 L1E; C:\Windows\System32\DRIVERS\L1E62x86.sys [55848 2000-01-01] (Atheros Communications, Inc.)
S3 MRxDAV; C:\Windows\system32\drivers\mrxdav.sys [116224 2014-12-19] (Microsoft Corporation) [File not signed]
R3 mrxsmb; C:\Windows\System32\DRIVERS\mrxsmb.sys [124416 2015-07-01] (Microsoft Corporation) [File not signed]
R3 mrxsmb10; C:\Windows\System32\DRIVERS\mrxsmb10.sys [225792 2015-07-01] (Microsoft Corporation) [File not signed]
R3 mrxsmb20; C:\Windows\System32\DRIVERS\mrxsmb20.sys [98304 2015-07-01] (Microsoft Corporation) [File not signed]
R3 NETwNs32; C:\Windows\System32\DRIVERS\NETwNs32.sys [7517696 2011-08-03] (Intel Corporation)
R2 npf; C:\Windows\System32\drivers\npf.sys [35088 2011-02-11] (CACE Technologies, Inc.)
R3 nuvotoncir; C:\Windows\System32\DRIVERS\nuvotoncir.sys [44544 2009-08-31] (Nuvoton Technology Corporation)
R3 nvvad_WaveExtensible; C:\Windows\System32\drivers\nvvad32v.sys [34080 2013-12-27] (NVIDIA Corporation)
R2 PEAUTH; C:\Windows\System32\drivers\peauth.sys [593920 2015-02-03] (Microsoft Corporation) [File not signed]
S3 RDPWD; C:\Windows\system32\Drivers\RDPWD.sys [184320 2014-07-17] (Microsoft Corporation) [File not signed]
R1 SCDEmu; C:\Windows\system32\Drivers\SCDEmu.sys [31644 2006-12-25] (PowerISO Computing, Inc.) [File not signed]
R3 SCREAMINGBDRIVER; C:\Windows\System32\drivers\ScreamingBAudio.sys [34896 2014-02-07] (Screaming Bee LLC)
S3 SWDUMon; C:\Windows\System32\DRIVERS\SWDUMon.sys [13464 2016-01-02] ()
R1 tdx; C:\Windows\System32\DRIVERS\tdx.sys [74752 2014-11-11] (Microsoft Corporation) [File not signed]
S3 tssecsrv; C:\Windows\System32\DRIVERS\tssecsrv.sys [31232 2014-07-17] (Microsoft Corporation) [File not signed]
S3 USBAAPL; C:\Windows\System32\Drivers\usbaapl.sys [45056 2015-06-17] (Apple, Inc.) [File not signed]
R2 {09F57980-3432-4AFC-957D-27AC45FAE1F5}; C:\Nainstalovano\Power DVD 13\PowerDVD13\Common\NavFilter\000.fcl [76560 2013-10-23] (CyberLink Corp.)
S3 CTIpHook; \SystemRoot\system32\Drivers\CTIpHook.sys [X]
S3 esgiguard; \??\C:\Program Files\Enigma Software Group\SpyHunter\esgiguard.sys [X]
S3 MBAMSwissArmy; \??\C:\Windows\system32\drivers\MBAMSwissArmy.sys [X]
U4 VBoxAswDrv; \??\C:\Nainstalovano\Avast\ng\vbox\VBoxAswDrv.sys [X]
==================== NetSvcs (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
==================== One Month Created files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2016-01-02 22:49 - 2016-01-02 22:49 - 00000000 ____D C:\FRST
2016-01-02 22:28 - 2016-01-02 22:28 - 00000000 _____ C:\Users\Paja\AppData\Local\{420565C7-551E-4DB4-A42D-D66A5D182EA7}
2016-01-02 22:28 - 2016-01-02 22:28 - 00000000 _____ C:\Users\Paja\AppData\Local\{260E69FE-667F-4EA6-AAA1-CDB82EE17888}
2016-01-02 18:23 - 2016-01-02 18:23 - 00000975 _____ C:\Users\Paja\Desktop\Install Kaspersky Internet Security version 16.0.0.614.lnk
2016-01-02 00:33 - 2015-12-29 01:00 - 319213865 _____ C:\Karel-Gott-2012-z-O2-areny-druhá-čast.webm
2016-01-02 00:32 - 2015-12-29 00:49 - 595946062 _____ C:\Karel Gott - O2 arena, 2012- první část.webm
2016-01-01 22:24 - 2016-01-01 22:25 - 21540440 _____ (Malwarebytes Corporation ) C:\Users\Paja\Downloads\mbam-setup-2.1.4.1018 (1).exe
2016-01-01 22:24 - 2016-01-01 22:24 - 21540440 _____ (Malwarebytes Corporation ) C:\Users\Paja\Downloads\mbam-setup-2.1.4.1018.exe
2016-01-01 22:12 - 2016-01-01 22:12 - 00000000 ____D C:\ProgramData\Kaspersky Lab Setup Files
2016-01-01 22:11 - 2016-01-01 22:12 - 01907824 _____ (Kaspersky Lab) C:\Users\Paja\Downloads\kis16.0.0.614en_8204 (1).exe
2016-01-01 22:11 - 2016-01-01 22:11 - 01907824 _____ (Kaspersky Lab) C:\Users\Paja\Downloads\kis16.0.0.614en_8204.exe
2015-12-31 18:11 - 2015-12-17 20:21 - 00579654 _____ C:\Na kolíčkách 2 2016.bmp
2015-12-29 23:27 - 2015-12-30 00:39 - 00000000 ____D C:\Anička proměny
2015-12-27 16:28 - 2016-01-01 22:43 - 00000000 ____D C:\ProgramData\TempMoudleSet
2015-12-27 16:28 - 2015-12-27 16:28 - 00000270 __RSH C:\ProgramData\ntuser.pol
2015-12-21 23:53 - 2015-12-17 20:18 - 01920054 _____ C:\Přání s textem 4 2016.bmp
2015-12-21 19:12 - 2015-12-21 19:15 - 00000000 ____D C:\dnes 21.12.2015
2015-12-20 22:24 - 2015-12-20 22:24 - 01920054 _____ C:\Přání s textem 3 2016_New.bmp
2015-12-20 22:23 - 2015-12-20 22:25 - 00003812 _____ C:\Přání s textem 3 2016_data.xml
2015-12-20 22:15 - 2015-12-17 20:18 - 01920054 _____ C:\Přání s textem 3 2016.bmp
2015-12-20 20:38 - 2015-12-20 20:50 - 00000000 ____D C:\fotky trhy výběr 2015
2015-12-20 20:13 - 2015-12-22 02:32 - 00000000 ____D C:\Vánoční trhy večer 2015
2015-12-18 17:55 - 2015-12-18 18:02 - 00000000 ____D C:\flash disk z.aloha dnes .18.12.2016
2015-12-18 01:39 - 2015-12-18 01:39 - 00322760 _____ (AVAST Software) C:\Windows\system32\aswBoot.exe
2015-12-18 01:39 - 2015-12-18 01:39 - 00043112 _____ (AVAST Software) C:\Windows\avastSS.scr
2015-12-17 21:42 - 2015-12-17 21:42 - 00002593 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office PowerPoint Viewer 2007.lnk
2015-12-17 21:42 - 2015-12-17 21:42 - 00000000 ____D C:\Program Files\Microsoft Office
2015-12-17 21:41 - 2015-12-17 21:41 - 00000000 ____D C:\Program Files\MSECache
2015-12-15 19:37 - 2015-12-15 20:01 - 00000000 ____D C:\Users\Paja\AppData\Roaming\iPhotoDraw
2015-12-15 19:37 - 2015-12-15 19:37 - 00001794 _____ C:\Users\Paja\Desktop\iPhotoDraw 2.0.lnk
2015-12-15 19:37 - 2015-12-15 19:37 - 00000000 ____D C:\Users\Paja\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\iPhotoDraw 2.0
2015-12-15 18:55 - 2015-12-15 18:55 - 00000000 ____D C:\Users\Paja\AppData\Local\kiwi.software.NET
2015-12-11 00:57 - 2015-12-11 22:52 - 00000000 ____D C:\Users\Paja\AppData\Roaming\Apple Computer
2015-12-11 00:57 - 2015-12-11 00:57 - 00001632 _____ C:\Users\Public\Desktop\iTunes.lnk
2015-12-11 00:57 - 2015-12-11 00:57 - 00000000 ____D C:\Users\Paja\AppData\Local\Apple Computer
2015-12-11 00:57 - 2015-12-11 00:57 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iTunes
2015-12-11 00:57 - 2015-12-11 00:57 - 00000000 ____D C:\ProgramData\Apple Computer
2015-12-11 00:57 - 2015-12-11 00:57 - 00000000 ____D C:\Program Files\iPod
2015-12-11 00:55 - 2015-12-11 00:55 - 00002519 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Apple Software Update.lnk
2015-12-11 00:55 - 2015-12-11 00:55 - 00000000 ____D C:\Users\Paja\AppData\Local\Apple
2015-12-11 00:55 - 2015-12-11 00:55 - 00000000 ____D C:\Program Files\Bonjour
2015-12-11 00:55 - 2015-12-11 00:55 - 00000000 ____D C:\Program Files\Apple Software Update
2015-12-11 00:54 - 2015-12-11 00:57 - 00000000 ____D C:\Program Files\Common Files\Apple
2015-12-11 00:54 - 2015-12-11 00:55 - 00000000 ____D C:\ProgramData\Apple
2015-12-07 15:23 - 2015-12-07 15:33 - 00000000 ____D C:\Vánoční trhy 2015
2015-12-05 22:23 - 2015-12-05 22:23 - 00000936 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore1d12fa330b3a975.job
2015-12-03 18:39 - 2015-12-03 18:39 - 00000000 ____D C:\Program Files\Common Files\AV
==================== One Month Modified files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2016-01-02 22:49 - 2009-07-14 03:37 - 00000000 ____D C:\Windows
2016-01-02 22:48 - 2014-04-11 15:32 - 00000000 ____D C:\Users\Paja\AppData\Roaming\Seznam.cz
2016-01-02 22:44 - 2014-04-11 16:05 - 00000384 _____ C:\Windows\Tasks\SlimDrivers Startup.job
2016-01-02 22:43 - 2015-09-22 16:11 - 00013464 _____ C:\Windows\system32\Drivers\SWDUMon.sys
2016-01-02 22:43 - 2014-04-11 15:21 - 00000936 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2016-01-02 22:43 - 2009-07-14 05:53 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2016-01-02 22:42 - 2014-04-11 15:21 - 00000936 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2016-01-02 21:57 - 2014-04-11 20:38 - 00000914 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job
2016-01-02 21:55 - 2009-07-14 05:34 - 00028352 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2016-01-02 21:55 - 2009-07-14 05:34 - 00028352 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2016-01-02 21:18 - 2014-04-11 21:02 - 00000000 ____D C:\Users\Paja\AppData\Roaming\uTorrent
2016-01-02 19:37 - 2010-11-21 02:16 - 00672046 _____ C:\Windows\system32\perfh005.dat
2016-01-02 19:37 - 2010-11-21 02:16 - 00142610 _____ C:\Windows\system32\perfc005.dat
2016-01-02 19:37 - 2010-11-20 22:01 - 01591750 _____ C:\Windows\system32\PerfStringBackup.INI
2016-01-02 19:37 - 2009-07-14 03:37 - 00000000 ____D C:\Windows\inf
2016-01-02 01:57 - 2015-11-22 22:54 - 00000000 ____D C:\Users\Paja\AppData\Roaming\vlc
2016-01-02 01:31 - 2015-02-21 21:07 - 00014011 _____ C:\Users\Paja\Desktop\Nový textový dokument (2).txt
2016-01-01 22:49 - 2014-04-11 15:15 - 00000000 ____D C:\Nainstalovano
2016-01-01 22:48 - 2014-06-24 14:04 - 00000000 ____D C:\Users\Paja\AppData\Local\CrashDumps
2015-12-31 22:42 - 2015-10-29 21:41 - 00000000 ____D C:\ProgramData\iSkysoft iMedia Converter Deluxe
2015-12-28 18:58 - 2014-04-11 20:38 - 00796864 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerApp.exe
2015-12-28 18:58 - 2014-04-11 20:38 - 00142528 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerCPLApp.cpl
2015-12-28 00:31 - 2014-09-13 09:03 - 00000000 ____D C:\s
2015-12-27 16:28 - 2015-09-22 16:30 - 00002331 _____ C:\Users\Public\Desktop\Google Chrome.lnk
2015-12-27 16:28 - 2015-09-19 13:42 - 00000000 ____D C:\Program Files\RayDld
2015-12-27 16:28 - 2014-06-06 10:22 - 00001098 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk
2015-12-27 16:28 - 2014-06-06 10:22 - 00001086 _____ C:\Users\Public\Desktop\Mozilla Firefox.lnk
2015-12-27 16:28 - 2014-04-11 15:40 - 00001078 _____ C:\Users\Public\Desktop\Opera.lnk
2015-12-27 16:28 - 2009-07-14 03:37 - 00000000 ___HD C:\Windows\system32\GroupPolicy
2015-12-26 10:51 - 2014-05-02 21:24 - 00000000 ____D C:\Program Files\Mozilla Maintenance Service
2015-12-20 01:04 - 2014-04-11 19:07 - 00000000 ____D C:\Users\Paja\AppData\Local\ElevatedDiagnostics
2015-12-20 00:03 - 2009-07-14 03:37 - 00000000 ____D C:\Windows\system32\NDF
2015-12-18 17:39 - 2014-04-11 15:21 - 00436360 _____ (AVAST Software) C:\Windows\system32\Drivers\aswsp.sys
2015-12-18 17:39 - 2014-04-11 15:21 - 00081168 _____ (AVAST Software) C:\Windows\system32\Drivers\aswmonflt.sys
2015-12-18 01:39 - 2014-04-27 17:18 - 00024016 _____ (AVAST Software) C:\Windows\system32\Drivers\aswHwid.sys
2015-12-18 01:39 - 2014-04-11 17:11 - 00020900 _____ C:\Users\Paja\Desktop\Nový textový dokument.txt
2015-12-18 01:39 - 2014-04-11 15:21 - 00794952 _____ (AVAST Software) C:\Windows\system32\Drivers\aswSnx.sys
2015-12-18 01:39 - 2014-04-11 15:21 - 00209432 _____ (AVAST Software) C:\Windows\system32\Drivers\aswVmm.sys
2015-12-18 01:39 - 2014-04-11 15:21 - 00117712 _____ (AVAST Software) C:\Windows\system32\Drivers\aswStm.sys
2015-12-18 01:39 - 2014-04-11 15:21 - 00081728 _____ (AVAST Software) C:\Windows\system32\Drivers\aswRdr2.sys
2015-12-18 01:39 - 2014-04-11 15:21 - 00049776 _____ (AVAST Software) C:\Windows\system32\Drivers\aswRvrt.sys
2015-12-15 22:58 - 2015-09-25 19:12 - 00000000 ____D C:\fotky poslat
2015-12-09 01:11 - 2014-04-11 19:52 - 00000000 ____D C:\Users\Paja\AppData\Roaming\AIMP3
2015-12-09 00:26 - 2014-05-05 21:41 - 00000000 ____D C:\Users\Paja\AppData\Roaming\dvdcss
2015-12-05 22:23 - 2015-09-19 22:34 - 00000936 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore1d0f322e751134a.job
==================== Files in the root of some directories =======
2014-08-08 23:17 - 2011-07-19 02:37 - 0003262 _____ () C:\Program Files\Falco.ico
2014-08-08 23:17 - 2011-07-19 03:05 - 0000046 _____ () C:\Program Files\Falco.url
2014-07-10 07:16 - 2014-07-10 07:16 - 2174976 _____ (Advanced Micro Devices Inc.) C:\Program Files\Common Files\atimpenc.dll
2014-04-17 22:50 - 2014-04-19 21:57 - 0087608 _____ () C:\Users\Paja\AppData\Roaming\inst.exe
2014-04-17 22:50 - 2014-04-19 21:57 - 0007887 _____ () C:\Users\Paja\AppData\Roaming\pcouffin.cat
2014-04-17 22:50 - 2014-04-19 21:57 - 0001144 _____ () C:\Users\Paja\AppData\Roaming\pcouffin.inf
2014-04-17 22:52 - 2014-04-19 21:57 - 0000034 _____ () C:\Users\Paja\AppData\Roaming\pcouffin.log
2014-04-17 22:50 - 2014-04-19 21:57 - 0047360 _____ (VSO Software) C:\Users\Paja\AppData\Roaming\pcouffin.sys
2014-04-17 22:52 - 2015-10-18 19:50 - 0000668 _____ () C:\Users\Paja\AppData\Roaming\vso_ts_preview.xml
2014-05-02 22:58 - 2014-05-02 22:58 - 0000001 _____ () C:\Users\Paja\AppData\Local\llftool.4.40.agreement
2015-10-15 21:09 - 2015-10-15 21:13 - 0033792 _____ () C:\Users\Paja\AppData\Local\Tempserver.exe
2016-01-02 22:28 - 2016-01-02 22:28 - 0000000 _____ () C:\Users\Paja\AppData\Local\{260E69FE-667F-4EA6-AAA1-CDB82EE17888}
2016-01-02 22:28 - 2016-01-02 22:28 - 0000000 _____ () C:\Users\Paja\AppData\Local\{420565C7-551E-4DB4-A42D-D66A5D182EA7}
2014-04-11 16:49 - 2014-04-11 16:49 - 0000000 ____H () C:\ProgramData\DP45977C.lfl
Some files in TEMP:
====================
C:\Users\Paja\AppData\Local\Temp\AskSLib.dll
C:\Users\Paja\AppData\Local\Temp\bdfilters.dll
C:\Users\Paja\AppData\Local\Temp\fp_pl_pfs_installer.exe
C:\Users\Paja\AppData\Local\Temp\FreemakeVideoConverterFull.exe
C:\Users\Paja\AppData\Local\Temp\FreemakeVideoDownloader_3.6.4.1.exe
C:\Users\Paja\AppData\Local\Temp\FreemakeVideoDownloader_3.6.4.3.exe
C:\Users\Paja\AppData\Local\Temp\FreeYouTubeDownload.exe
C:\Users\Paja\AppData\Local\Temp\hp_u_23828328.exe
C:\Users\Paja\AppData\Local\Temp\iupdate.exe
C:\Users\Paja\AppData\Local\Temp\jna1334869850114248042.dll
C:\Users\Paja\AppData\Local\Temp\KMP_3.2.0.0.exe
C:\Users\Paja\AppData\Local\Temp\listicka-partner-13415-1.1.2-offline.exe
C:\Users\Paja\AppData\Local\Temp\listicka.exe
C:\Users\Paja\AppData\Local\Temp\maucampoSetup.exe
C:\Users\Paja\AppData\Local\Temp\ose00000.exe
C:\Users\Paja\AppData\Local\Temp\OutpostSecuritySuiteProInstall_NoBase.exe
C:\Users\Paja\AppData\Local\Temp\ReimagePackage.exe
C:\Users\Paja\AppData\Local\Temp\SkypeSetup.exe
C:\Users\Paja\AppData\Local\Temp\sp-downloader.exe
C:\Users\Paja\AppData\Local\Temp\SpeedUpMyComputer.exe
C:\Users\Paja\AppData\Local\Temp\tmd_34011571.exe
C:\Users\Paja\AppData\Local\Temp\tmd_34012617.exe
C:\Users\Paja\AppData\Local\Temp\tmd_34013608.exe
C:\Users\Paja\AppData\Local\Temp\tmd_34014889.exe
C:\Users\Paja\AppData\Local\Temp\tmd_34016271.exe
C:\Users\Paja\AppData\Local\Temp\tmd_34016886.exe
C:\Users\Paja\AppData\Local\Temp\tmd_34017186.exe
C:\Users\Paja\AppData\Local\Temp\tmd_34017419.exe
C:\Users\Paja\AppData\Local\Temp\tmd_34017597.exe
C:\Users\Paja\AppData\Local\Temp\tmd_34017755.exe
C:\Users\Paja\AppData\Local\Temp\tmd_34018251.exe
C:\Users\Paja\AppData\Local\Temp\tmd_34018466.exe
C:\Users\Paja\AppData\Local\Temp\tmd_34018741.exe
C:\Users\Paja\AppData\Local\Temp\WinUpdat.exe
C:\Users\Paja\AppData\Local\Temp\YandexWorking.exe
C:\Users\Paja\AppData\Local\Temp\{E638ABC1-0067-474b-A379-87CFE81E7848}.exe
C:\Users\Paja\AppData\Local\Temp\~ACE3.exe
C:\Users\Paja\AppData\Local\Temp\~D4EB.exe
==================== Bamital & volsnap =================
(There is no automatic fix for files that do not pass verification.)
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\system32\winlogon.exe => MD5 is legit
C:\Windows\system32\wininit.exe => File is digitally signed
C:\Windows\system32\svchost.exe => File is digitally signed
C:\Windows\system32\services.exe
[2015-05-13 14:28] - [2015-04-13 04:19] - 0259072 ____A (Microsoft Corporation) 0780A42DBD7D9969F9BF4A19AA4285B5
C:\Windows\system32\User32.dll => File is digitally signed
C:\Windows\system32\userinit.exe => File is digitally signed
C:\Windows\system32\rpcss.dll => File is digitally signed
C:\Windows\system32\dnsapi.dll => File is digitally signed
C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed
LastRegBack: 2015-12-30 20:38
==================== End of FRST.txt ============================
Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version:31-12-2015
Ran by Paja (administrator) on PAJA-NOTEBOOK (02-01-2016 22:49:23)
Running from D:\Stažené soubory
Loaded Profiles: Paja (Available Profiles: Paja)
Platform: Microsoft Windows 7 Home Premium Service Pack 1 (X86) Language: Čeština (Česká republika)
Internet Explorer Version 11 (Default browser: FF)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/33 ... scan-tool/
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(AVAST Software) C:\Nainstalovano\Avast\AvastSvc.exe
(Apple Inc.) C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(CyberLink) C:\Nainstalovano\Power DVD 13\PowerDVD13\Kernel\DMS\CLMSMonitorServicePDVD13.exe
(CyberLink) C:\Nainstalovano\Power DVD 13\PowerDVD13\Kernel\DMS\CLMSServerPDVD13.exe
(Ellora Assets Corp.) C:\Nainstalovano\Freemake\CaptureLib\CaptureLibService.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NetService\NvNetworkService.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
() C:\Nainstalovano\reaConverter 7 Standard\rc_service.exe
() C:\Nainstalovano\ProShow\scsiaccess.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
(SlimWare Utilities, Inc.) C:\Program Files\SlimDrivers\SlimDrivers.exe
(AVAST Software) C:\Nainstalovano\Avast\AvastUI.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe
(CyberLink Corp.) C:\Nainstalovano\Power DVD 13\PowerDVD13\PowerDVD13Agent.exe
(Microsoft Corporation) C:\Nainstalovano\Microsoft Office Enterprise 2007\Office12\GrooveMonitor.exe
(NEC Electronics Corporation) C:\Program Files\Western Digital\USB 3.0 Host Controller Driver\Application\nusb3mon.exe
(PowerISO Computing, Inc.) C:\Nainstalovano\PowerISO\PWRISOVM.EXE
() C:\Program Files\Common Files\Freemake Shared\ProductUpdater\ProductUpdater.exe
(iSkySoft) C:\Program Files\Common Files\iSkysoft\iSkysoft Helper Compact\ISHelper.exe
(Apple Inc.) C:\Nainstalovano\Itunes\iTunesHelper.exe
(Microsoft Corporation) C:\Program Files\Windows Sidebar\sidebar.exe
(ZONER software) C:\Nainstalovano\Photo Studio 17\Program32\ZPSTray.exe
(McAfee, Inc.) C:\Program Files\McAfee Security Scan\3.8.150\SSScheduler.exe
() C:\Users\Paja\AppData\Roaming\Seznam.cz\bin\szndesktop.exe
(Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe
(Microsoft Corporation) C:\Windows\System32\GWX\GWX.exe
(Microsoft Corporation) C:\Windows\System32\wbem\unsecapp.exe
(Mozilla Corporation) C:\Nainstalovano\Mozilla Firefox\firefox.exe
==================== Registry (Whitelisted) ===========================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [AvastUI.exe] => C:\Nainstalovano\Avast\AvastUI.exe [7021880 2015-12-18] (AVAST Software)
HKLM\...\Run: [seznam-listicka-distribuce] => C:\Program Files\Seznam.cz\distribution\szninstall.exe [1062472 2013-05-16] ()
HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe [12021464 2000-01-01] (Realtek Semiconductor)
HKLM\...\Run: [PowerDVD13Agent] => C:\Nainstalovano\Power DVD 13\PowerDVD13\PowerDVD13Agent.exe [517144 2013-10-23] (CyberLink Corp.)
HKLM\...\Run: [NeroFilterCheck] => C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe [155648 2006-01-12] (Nero AG)
HKLM\...\Run: [GrooveMonitor] => C:\Nainstalovano\Microsoft Office Enterprise 2007\Office12\GrooveMonitor.exe [31016 2006-10-26] (Microsoft Corporation)
HKLM\...\Run: [NUSB3MON] => C:\Program Files\Western Digital\USB 3.0 Host Controller Driver\Application\nusb3mon.exe [106496 2009-11-20] (NEC Electronics Corporation)
HKLM\...\Run: [PWRISOVM.EXE] => C:\Nainstalovano\PowerISO\PWRISOVM.EXE [200704 2006-12-25] (PowerISO Computing, Inc.)
HKLM\...\Run: [ProductUpdater] => C:\Program Files\Common Files\Freemake Shared\ProductUpdater\ProductUpdater.exe [62464 2015-06-18] ()
HKLM\...\Run: [ChicoSys] => C:\Windows\system32\cc32\webtmr.exe
HKLM\...\Run: [iSkysoft Helper Compact.exe] => C:\Program Files\Common Files\iSkysoft\iSkysoft Helper Compact\ISHelper.exe [2066432 2014-10-31] (iSkySoft)
HKLM\...\Run: [DelaypluginInstall] => C:\ProgramData\iSkysoft\Video Converter Ultimate\DelayPluginI.exe [1960248 2015-10-29] ()
HKLM\...\Run: [iTunesHelper] => C:\Nainstalovano\Itunes\iTunesHelper.exe [157456 2015-10-16] (Apple Inc.)
HKLM\Software\Policies\Microsoft\Windows NT\SystemRestore: [DisableSR/DisableConfig] <===== ATTENTION
HKU\S-1-5-21-203695958-539750940-1501531493-1000\...\Run: [DAEMON Tools Lite] => C:\Nainstalovano\DAEMON Tools Lite\DTLite.exe [3696912 2014-03-04] (Disc Soft Ltd)
HKU\S-1-5-21-203695958-539750940-1501531493-1000\...\Run: [cz.seznam.software.autoupdate] => C:\Users\Paja\AppData\Roaming\Seznam.cz\szninstall.exe [1062472 2013-05-16] ()
HKU\S-1-5-21-203695958-539750940-1501531493-1000\...\Run: [cz.seznam.software.szndesktop] => C:\Users\Paja\AppData\Roaming\Seznam.cz\bin\wszndesktop.exe [103080 2015-05-26] ()
HKU\S-1-5-21-203695958-539750940-1501531493-1000\...\Run: [PowerDVD13] => C:\Nainstalovano\Power DVD 13\PowerDVD13\PDVDLP.exe [470792 2013-10-23] (CyberLink Corp.)
HKU\S-1-5-21-203695958-539750940-1501531493-1000\...\Run: [Super MP3 Download] => C:\Nainstalovano\SuperMp3Download\SuperMp3Download.exe
HKU\S-1-5-21-203695958-539750940-1501531493-1000\...\Run: [Zoner Photo Studio Autoupdate] => C:\NAINSTALOVANO\PHOTO STUDIO 17\Program32\ZPSTRAY.EXE [563416 2015-07-12] (ZONER software)
HKU\S-1-5-21-203695958-539750940-1501531493-1000\...\Policies\system: [DisableLockWorkstation] 0
HKU\S-1-5-21-203695958-539750940-1501531493-1000\...\Policies\system: [DisableClock] 0
HKU\S-1-5-21-203695958-539750940-1501531493-1000\...\Policies\Explorer: [NoSaveSettings] 0
HKU\S-1-5-21-203695958-539750940-1501531493-1000\...\Policies\Explorer: [NoFind] 0
HKU\S-1-5-21-203695958-539750940-1501531493-1000\...\Policies\Explorer: [RestrictRun] 0
HKU\S-1-5-21-203695958-539750940-1501531493-1000\...\MountPoints2: {a502a618-d5c3-11e3-85c8-00238b4d4eb9} - I:\Unlock.exe autoplay=true
HKU\S-1-5-21-203695958-539750940-1501531493-1000\...\MountPoints2: {fed0b4e4-c241-11e3-9ac1-00238b4d4eb9} - F:\Unlock.exe autoplay=true
IFEO: [Debugger] logonui.exe
ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Nainstalovano\Avast\ashShell.dll [2015-12-18] (AVAST Software)
ShellIconOverlayIdentifiers: [Groove Explorer Icon Overlay 1 (GFS Unread Stub)] -> {99FD978C-D287-4F50-827F-B2C658EDA8E7} => C:\Nainstalovano\Microsoft Office Enterprise 2007\Office12\GrooveShellExtensions.dll [2006-10-26] (Microsoft Corporation)
ShellIconOverlayIdentifiers: [Groove Explorer Icon Overlay 2 (GFS Stub)] -> {AB5C5600-7E6E-4B06-9197-9ECEF74D31CC} => C:\Nainstalovano\Microsoft Office Enterprise 2007\Office12\GrooveShellExtensions.dll [2006-10-26] (Microsoft Corporation)
ShellIconOverlayIdentifiers: [Groove Explorer Icon Overlay 2.5 (GFS Unread Folder)] -> {920E6DB1-9907-4370-B3A0-BAFC03D81399} => C:\Nainstalovano\Microsoft Office Enterprise 2007\Office12\GrooveShellExtensions.dll [2006-10-26] (Microsoft Corporation)
ShellIconOverlayIdentifiers: [Groove Explorer Icon Overlay 3 (GFS Folder)] -> {16F3DD56-1AF5-4347-846D-7C10C4192619} => C:\Nainstalovano\Microsoft Office Enterprise 2007\Office12\GrooveShellExtensions.dll [2006-10-26] (Microsoft Corporation)
ShellIconOverlayIdentifiers: [Groove Explorer Icon Overlay 4 (GFS Unread Mark)] -> {2916C86E-86A6-43FE-8112-43ABE6BF8DCC} => C:\Nainstalovano\Microsoft Office Enterprise 2007\Office12\GrooveShellExtensions.dll [2006-10-26] (Microsoft Corporation)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\McAfee Security Scan Plus.lnk [2014-06-16]
ShortcutTarget: McAfee Security Scan Plus.lnk -> C:\Program Files\McAfee Security Scan\3.8.150\SSScheduler.exe (McAfee, Inc.)
GroupPolicy: Restriction - Chrome <======= ATTENTION
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
ProxyServer: [S-1-5-21-203695958-539750940-1501531493-1000] => 127.0.0.1:8118
AutoConfigURL: [S-1-5-21-203695958-539750940-1501531493-1000] => 127.0.0.1:8118
Winsock: Catalog5 08 C:\Program Files\Bonjour\mdnsNSP.dll [122128 2015-08-12] (Apple Inc.)
Hosts: There are more than one entry in Hosts. See Hosts section of Addition.txt
Tcpip\Parameters: [DhcpNameServer] 192.168.1.1
Tcpip\..\Interfaces\{40DC63AB-CEE4-4DC9-B408-F49CC64F1E51}: [DhcpNameServer] 192.168.1.1
Tcpip\..\Interfaces\{4BC8D7B9-962E-4783-9952-1E606FCB20A9}: [NameServer] 10.1.1.0,10.1.1.100
Internet Explorer:
==================
HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer: Restriction <======= ATTENTION
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.google.com
HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.google.com
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.google.com
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://www.google.com
SearchScopes: HKLM -> {20B9D1AE-AD1A-38B4-87FE-AF278DA9861D} URL = hxxps://gosearch.me/?q={searchTerms}&u=8a2ccd6e0fb051f271b9fdac2c41a2ef&c=DP3221&src=srch&inst=1442925936
SearchScopes: HKU\S-1-5-21-203695958-539750940-1501531493-1000 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://search.seznam.cz/?sourceid=quicksearch_6826&q={searchTerms}
SearchScopes: HKU\S-1-5-21-203695958-539750940-1501531493-1000 -> 1500C81568E2C9D8F17E29C71ECBB74C URL = hxxp://videa.seznam.cz/?q={searchTerms}
SearchScopes: HKU\S-1-5-21-203695958-539750940-1501531493-1000 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://search.seznam.cz/?sourceid=quicksearch_6826&q={searchTerms}
SearchScopes: HKU\S-1-5-21-203695958-539750940-1501531493-1000 -> {20B9D1AE-AD1A-38B4-87FE-AF278DA9861D} URL = hxxps://gosearch.me/?q={searchTerms}&u=8a2ccd6e0fb051f271b9fdac2c41a2ef&c=DP3221&src=srch&inst=1442925936
SearchScopes: HKU\S-1-5-21-203695958-539750940-1501531493-1000 -> {277CAC54-E9ED-4D8D-A5EE-B68C989B0702} URL = hxxp://slovnik.seznam.cz/?q={searchTerms}&lang=cz_en&sourceid=QuickSearch_13415
SearchScopes: HKU\S-1-5-21-203695958-539750940-1501531493-1000 -> {689B78F0-8B45-4ECB-9281-07C3EDCB4AC9} URL = hxxp://encyklopedie.seznam.cz/search?q={searchTerms}&sourceid=QuickSearch_13415
SearchScopes: HKU\S-1-5-21-203695958-539750940-1501531493-1000 -> {8C0F53C9-4A67-405B-A162-47CB1D92A819} URL = hxxp://slovnik.seznam.cz/?q={searchTerms}&lang=en_cz&sourceid=QuickSearch_13415
SearchScopes: HKU\S-1-5-21-203695958-539750940-1501531493-1000 -> {ABE66342-AAA7-446E-A568-33A94614EBF0} URL = hxxp://www.zbozi.cz/?q={searchTerms}&r=campmoz ... arch_13415
SearchScopes: HKU\S-1-5-21-203695958-539750940-1501531493-1000 -> {BC7A8C3E-1862-46C6-AB34-E0AE9DAE2F9F} URL = hxxp://www.novinky.cz/hledej?w={searchTerms}&s ... arch_13415
SearchScopes: HKU\S-1-5-21-203695958-539750940-1501531493-1000 -> {DC0205BF-941D-4EF3-A735-94D96E507A52} URL = hxxp://www.firmy.cz/?q={searchTerms}&sourceid= ... arch_13415
SearchScopes: HKU\S-1-5-21-203695958-539750940-1501531493-1000 -> {E3BF7B2D-C987-462D-9BF9-92F2FCC615DA} URL = hxxp://tv.seznam.cz/hledej?w={searchTerms}&sourceid=QuickSearch_13415
SearchScopes: HKU\S-1-5-21-203695958-539750940-1501531493-1000 -> {EF7216C8-7796-4135-8706-0946085FD933} URL = hxxp://www.mapy.cz/?query={searchTerms}&source ... arch_13415
BHO: No Name -> {0E8A89AD-95D7-40EB-8D9D-083EF7066A01} -> No File
BHO: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Nainstalovano\Microsoft Office Enterprise 2007\Office12\GrooveShellExtensions.dll [2006-10-26] (Microsoft Corporation)
BHO: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Nainstalovano\Avast\aswWebRepIE.dll [2015-12-18] (AVAST Software)
BHO: iSkysoft iMedia Converter Deluxe 5.1.0 -> {AEAF002F-E6D8-4A21-ABD3-2B309B79A6CE} -> C:\ProgramData\iSkysoft\Video Converter Ultimate\WSBrowserAppMgr.dll [2015-10-29] (Wondershare)
BHO: No Name -> {D5FEC983-01DB-414A-9456-AF95AC9ED7B5} -> No File
Toolbar: HKU\S-1-5-21-203695958-539750940-1501531493-1000 -> No Name - {91397D20-1446-11D4-8AF4-0040CA1127B6} - No File
Handler: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Nainstalovano\Microsoft Office Enterprise 2007\Office12\GrooveSystemServices.dll [2006-10-26] (Microsoft Corporation)
Handler: mso-minsb-roaming.16 - {83C25742-A9F7-49FB-9138-434302C88D07} - C:\Program Files\Microsoft Office\root\Office16\MSOSB.DLL No File
Handler: mso-minsb.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files\Microsoft Office\root\Office16\MSOSB.DLL No File
Handler: osf-roaming.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files\Microsoft Office\root\Office16\MSOSB.DLL No File
Handler: osf.16 - {5504BE45-A83B-4808-900A-3A5C36E7F77A} - C:\Program Files\Microsoft Office\root\Office16\MSOSB.DLL No File
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll [2014-05-02] (Skype Technologies)
Handler: WSISVCUchrome - {78A543EB-3A61-4ED3 - No File
StartMenuInternet: IEXPLORE.EXE - C:\Program Files\Internet Explorer\iexplore.exe hxxp://www.piesearch.com/?type=sc&ts=145123009 ... 0e25ff60bc
FireFox:
========
FF ProfilePath: C:\Users\Paja\AppData\Roaming\Mozilla\Firefox\Profiles\3456uct3.default
FF Homepage: hxxps://www.seznam.cz/
FF NetworkProxy: "socks_remote_dns", true
FF NetworkProxy: "type", 4
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF32_20_0_0_267.dll [2015-12-28] ()
FF Plugin: @Apple.com/iTunes,version=1.0 -> C:\Nainstalovano\Itunes\Mozilla Plugins\npitunes.dll [2015-10-08] ()
FF Plugin: @microsoft.com/GENUINE -> disabled [No File]
FF Plugin: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files\Microsoft Office\root\Office16\NPSPWRAP.DLL [No File]
FF Plugin: @photodex.com/PhotodexPresenter -> C:\Program Files\Photodex Presenter\npPxPlay.dll [2014-11-11] ( )
FF Plugin: @tools.google.com/Google Update;version=3 -> C:\Program Files\Google\Update\1.3.29.1\npGoogleUpdate3.dll [2015-12-05] (Google Inc.)
FF Plugin: @tools.google.com/Google Update;version=9 -> C:\Program Files\Google\Update\1.3.29.1\npGoogleUpdate3.dll [2015-12-05] (Google Inc.)
FF Plugin: @videolan.org/vlc,version=2.1.5 -> C:\Nainstalovano\VLC\npvlc.dll [2015-04-13] (VideoLAN)
FF Plugin: @videolan.org/vlc,version=2.2.1 -> C:\Nainstalovano\VLC\npvlc.dll [2015-04-13] (VideoLAN)
FF Plugin: Adobe Reader -> C:\Program Files\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll [2015-09-30] (Adobe Systems Inc.)
FF Extension: Seznam lištička - C:\Users\Paja\AppData\Roaming\Mozilla\Firefox\Profiles\3456uct3.default\Extensions\{ea614400-e918-4741-9a97-7a972ff7c30b} [2015-12-12]
FF HKLM\...\Firefox\Extensions: [wrc@avast.com] - C:\Nainstalovano\Avast\WebRep\FF
FF Extension: Avast Online Security - C:\Nainstalovano\Avast\WebRep\FF [2015-12-18]
FF HKLM\...\Firefox\Extensions: [sp@avast.com] - C:\Nainstalovano\Avast\SafePrice\FF
FF Extension: Avast SafePrice - C:\Nainstalovano\Avast\SafePrice\FF [2015-12-18]
FF HKLM\...\Firefox\Extensions: [ISVCU@iSkysoft.com] - C:\ProgramData\iSkysoft\Video Converter Ultimate\ISVCU@iSkysoft.com
FF Extension: iSkysoft iMedia Converter Deluxe - C:\ProgramData\iSkysoft\Video Converter Ultimate\ISVCU@iSkysoft.com [2015-10-29] [not signed]
FF HKU\S-1-5-21-203695958-539750940-1501531493-1000\...\Firefox\Extensions: [{e4f94d1e-2f53-401e-8885-681602c0ddd8}] - C:\ProgramData\McAfee Security Scan\Extensions\{e4f94d1e-2f53-401e-8885-681602c0ddd8}.xpi => not found
StartMenuInternet: FIREFOX.EXE - C:\Nainstalovano\Mozilla Firefox\firefox.exe hxxp://www.piesearch.com/?type=sc&ts=145123009 ... 0e25ff60bc
Chrome:
=======
CHR HomePage: Default -> hxxp://www.seznam.cz/
CHR StartupUrls: Default -> "hxxps://www.seznam.cz/"
CHR Profile: C:\Users\Paja\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (Dokumenty Google) - C:\Users\Paja\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2015-02-13]
CHR Extension: (Disk Google) - C:\Users\Paja\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2015-10-22]
CHR Extension: (Seznam Lištička - Email) - C:\Users\Paja\AppData\Local\Google\Chrome\User Data\Default\Extensions\bgjpfhpjcgdppjbgnpnjllokbmcdllig [2015-02-17]
CHR Extension: (Seznam Lištička - Slovník) - C:\Users\Paja\AppData\Local\Google\Chrome\User Data\Default\Extensions\blmojkbhnkkphngknkmgccmlenfaelkd [2014-04-11]
CHR Extension: (YouTube) - C:\Users\Paja\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2015-09-25]
CHR Extension: (Vyhledávání Google) - C:\Users\Paja\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2015-11-03]
CHR Extension: (Dokumenty Google offline) - C:\Users\Paja\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2015-11-21]
CHR Extension: (Avast Online Security) - C:\Users\Paja\AppData\Local\Google\Chrome\User Data\Default\Extensions\gomekmidlodglbbmalcneegieacbdmki [2015-11-03]
CHR Extension: (Platby Internetového obchodu Chrome) - C:\Users\Paja\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2015-08-04]
CHR Extension: (Seznam Lištička - Rychlá volba) - C:\Users\Paja\AppData\Local\Google\Chrome\User Data\Default\Extensions\olfeabkoenfaoljndfecamgilllcpiak [2015-11-03]
CHR Extension: (Gmail) - C:\Users\Paja\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2015-04-08]
CHR HKLM\...\Chrome\Extension: [bopakagnckmlgajfccecajhnimjiiedh] - hxxp://clients2.google.com/service/update2/crx
CHR HKLM\...\Chrome\Extension: [gomekmidlodglbbmalcneegieacbdmki] - C:\Nainstalovano\Avast\WebRep\Chrome\aswWebRepChrome.crx [2015-12-18]
StartMenuInternet: Google Chrome - C:\Program Files\Google\Chrome\Application\chrome.exe hxxp://www.piesearch.com/?type=sc&ts=145123009 ... 0e25ff60bc
Opera:
=======
OPR StartupUrls: "hxxp://www.seznam.cz/?clid=6826"
StartMenuInternet: (HKLM) OperaStable - C:\Nainstalovano\Opera\Launcher.exe hxxp://www.piesearch.com/?type=sc&ts=145123009 ... 0e25ff60bc
==================== Services (Whitelisted) ========================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R3 AeLookupSvc; C:\Windows\System32\aelupsvc.dll [62464 2015-03-04] (Microsoft Corporation) [File not signed]
S3 AppIDSvc; C:\Windows\System32\appidsvc.dll [27648 2015-02-03] (Microsoft Corporation) [File not signed]
S3 Appinfo; C:\Windows\System32\appinfo.dll [47104 2015-06-15] (Microsoft Corporation) [File not signed]
R2 AudioEndpointBuilder; C:\Windows\System32\Audiosrv.dll [475136 2015-02-03] (Microsoft Corporation) [File not signed]
R2 Audiosrv; C:\Windows\System32\Audiosrv.dll [475136 2015-02-03] (Microsoft Corporation) [File not signed]
R2 avast! Antivirus; C:\Nainstalovano\Avast\AvastSvc.exe [226440 2015-12-18] (AVAST Software)
R2 CryptSvc; C:\Windows\system32\cryptsvc.dll [143872 2015-04-27] (Microsoft Corporation) [File not signed]
R2 CyberLink PowerDVD 13 Media Server Monitor Service; C:\Nainstalovano\Power DVD 13\PowerDVD13\Kernel\DMS\CLMSMonitorServicePDVD13.exe [77576 2013-10-23] (CyberLink)
R2 CyberLink PowerDVD 13 Media Server Service; C:\Nainstalovano\Power DVD 13\PowerDVD13\Kernel\DMS\CLMSServerPDVD13.exe [327432 2013-10-23] (CyberLink)
R2 DiagTrack; C:\Windows\system32\diagtrack.dll [853504 2015-05-25] (Microsoft Corporation) [File not signed]
S3 EFS; C:\Windows\System32\lsass.exe [22528 2015-07-01] (Microsoft Corporation) [File not signed]
R2 FontCache; C:\Windows\system32\FntCache.dll [909312 2015-04-20] (Microsoft Corporation) [File not signed]
R2 FreemakeVideoCapture; C:\Nainstalovano\Freemake\CaptureLib\CaptureLibService.exe [9216 2014-04-17] (Ellora Assets Corp.) [File not signed]
S3 IEEtwCollectorService; C:\Windows\system32\IEEtwCollector.exe [102912 2015-06-19] (Microsoft Corporation) [File not signed]
R3 KeyIso; C:\Windows\system32\lsass.exe [22528 2015-07-01] (Microsoft Corporation) [File not signed]
S3 Microsoft Office Groove Audit Service; C:\Nainstalovano\Microsoft Office Enterprise 2007\Office12\GrooveAuditService.exe [65824 2006-10-26] (Microsoft Corporation)
S3 msiserver; C:\Windows\System32\msiexec.exe [73216 2015-06-15] (Microsoft Corporation) [File not signed]
S3 NBService; C:\Nainstalovano\Nero 7\Nero BackItUp\NBService.exe [774144 2006-11-10] (Nero AG) [File not signed]
S3 Netlogon; C:\Windows\system32\lsass.exe [22528 2015-07-01] (Microsoft Corporation) [File not signed]
R2 NlaSvc; C:\Windows\System32\nlasvc.dll [242688 2014-12-06] (Microsoft Corporation) [File not signed]
R2 NvNetworkService; C:\Program Files\NVIDIA Corporation\NetService\NvNetworkService.exe [1593632 2014-02-05] (NVIDIA Corporation)
R2 NvStreamSvc; C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe [15904544 2014-02-05] (NVIDIA Corporation)
R3 PcaSvc; C:\Windows\System32\pcasvc.dll [157184 2015-02-03] (Microsoft Corporation) [File not signed]
R2 ProfSvc; C:\Windows\system32\profsvc.dll [164864 2014-12-19] (Microsoft Corporation) [File not signed]
S3 ProtectedStorage; C:\Windows\system32\lsass.exe [22528 2015-07-01] (Microsoft Corporation) [File not signed]
R2 reaConverter_service; C:\Nainstalovano\reaConverter 7 Standard\rc_service.exe [2129408 2015-06-19] () [File not signed]
R2 SamSs; C:\Windows\system32\lsass.exe [22528 2015-07-01] (Microsoft Corporation) [File not signed]
R2 ScsiAccess; C:\Nainstalovano\ProShow\ScsiAccess.exe [186760 2014-11-11] ()
S3 TermService; C:\Windows\System32\termsrv.dll [523776 2014-10-14] (Microsoft Corporation) [File not signed]
S3 VaultSvc; C:\Windows\system32\lsass.exe [22528 2015-07-01] (Microsoft Corporation) [File not signed]
R3 WdiServiceHost; C:\Windows\system32\wdi.dll [76800 2015-01-09] (Microsoft Corporation) [File not signed]
R3 WdiSystemHost; C:\Windows\system32\wdi.dll [76800 2015-01-09] (Microsoft Corporation) [File not signed]
R2 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [680960 2013-05-27] (Microsoft Corporation)
S3 WinRM; C:\Windows\system32\WsmSvc.dll [1177088 2014-10-03] (Microsoft Corporation) [File not signed]
R2 wuauserv; C:\Windows\system32\wuaueng.dll [2057216 2015-07-09] (Microsoft Corporation) [File not signed]
U4 AvastVBoxSvc; "C:\Nainstalovano\Avast\ng\vbox\AvastVBoxSVC.exe" [X]
S2 EvtEng; C:\Program Files\Intel\WiFi\bin\EvtEng.exe [X]
S2 MustangService_2015_10_10; C:\ProgramData\TempMoudleSet\MustangSer2728.exe [X]
S3 MyWiFiDHCPDNS; C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe [X]
S2 RegSrvc; C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe [X]
===================== Drivers (Whitelisted) ==========================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
S3 AMPPAL; C:\Windows\System32\DRIVERS\AMPPAL.sys [243712 2011-08-08] (Windows (R) Win 7 DDK provider)
S3 AppID; C:\Windows\system32\drivers\appid.sys [50176 2015-02-03] (Microsoft Corporation) [File not signed]
R2 aswHwid; C:\Windows\system32\drivers\aswHwid.sys [24016 2015-12-18] (AVAST Software)
R2 aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [81168 2015-12-18] (AVAST Software)
R1 aswRdr; C:\Windows\system32\drivers\aswRdr2.sys [81728 2015-12-18] (AVAST Software)
R0 aswRvrt; C:\Windows\system32\Drivers\aswRvrt.sys [49776 2015-12-18] (AVAST Software)
R1 aswSnx; C:\Windows\system32\drivers\aswSnx.sys [794952 2015-12-18] (AVAST Software)
R1 aswSP; C:\Windows\system32\drivers\aswSP.sys [436360 2015-12-18] (AVAST Software)
R2 aswStm; C:\Windows\system32\drivers\aswStm.sys [117712 2015-12-18] (AVAST Software)
R0 aswVmm; C:\Windows\system32\Drivers\aswVmm.sys [209432 2015-12-18] (AVAST Software)
R1 dtsoftbus01; C:\Windows\System32\DRIVERS\dtsoftbus01.sys [243128 2014-04-11] (Disc Soft Ltd)
R3 HTTP; C:\Windows\System32\drivers\HTTP.sys [514560 2015-02-25] (Microsoft Corporation) [File not signed]
R3 L1E; C:\Windows\System32\DRIVERS\L1E62x86.sys [55848 2000-01-01] (Atheros Communications, Inc.)
S3 MRxDAV; C:\Windows\system32\drivers\mrxdav.sys [116224 2014-12-19] (Microsoft Corporation) [File not signed]
R3 mrxsmb; C:\Windows\System32\DRIVERS\mrxsmb.sys [124416 2015-07-01] (Microsoft Corporation) [File not signed]
R3 mrxsmb10; C:\Windows\System32\DRIVERS\mrxsmb10.sys [225792 2015-07-01] (Microsoft Corporation) [File not signed]
R3 mrxsmb20; C:\Windows\System32\DRIVERS\mrxsmb20.sys [98304 2015-07-01] (Microsoft Corporation) [File not signed]
R3 NETwNs32; C:\Windows\System32\DRIVERS\NETwNs32.sys [7517696 2011-08-03] (Intel Corporation)
R2 npf; C:\Windows\System32\drivers\npf.sys [35088 2011-02-11] (CACE Technologies, Inc.)
R3 nuvotoncir; C:\Windows\System32\DRIVERS\nuvotoncir.sys [44544 2009-08-31] (Nuvoton Technology Corporation)
R3 nvvad_WaveExtensible; C:\Windows\System32\drivers\nvvad32v.sys [34080 2013-12-27] (NVIDIA Corporation)
R2 PEAUTH; C:\Windows\System32\drivers\peauth.sys [593920 2015-02-03] (Microsoft Corporation) [File not signed]
S3 RDPWD; C:\Windows\system32\Drivers\RDPWD.sys [184320 2014-07-17] (Microsoft Corporation) [File not signed]
R1 SCDEmu; C:\Windows\system32\Drivers\SCDEmu.sys [31644 2006-12-25] (PowerISO Computing, Inc.) [File not signed]
R3 SCREAMINGBDRIVER; C:\Windows\System32\drivers\ScreamingBAudio.sys [34896 2014-02-07] (Screaming Bee LLC)
S3 SWDUMon; C:\Windows\System32\DRIVERS\SWDUMon.sys [13464 2016-01-02] ()
R1 tdx; C:\Windows\System32\DRIVERS\tdx.sys [74752 2014-11-11] (Microsoft Corporation) [File not signed]
S3 tssecsrv; C:\Windows\System32\DRIVERS\tssecsrv.sys [31232 2014-07-17] (Microsoft Corporation) [File not signed]
S3 USBAAPL; C:\Windows\System32\Drivers\usbaapl.sys [45056 2015-06-17] (Apple, Inc.) [File not signed]
R2 {09F57980-3432-4AFC-957D-27AC45FAE1F5}; C:\Nainstalovano\Power DVD 13\PowerDVD13\Common\NavFilter\000.fcl [76560 2013-10-23] (CyberLink Corp.)
S3 CTIpHook; \SystemRoot\system32\Drivers\CTIpHook.sys [X]
S3 esgiguard; \??\C:\Program Files\Enigma Software Group\SpyHunter\esgiguard.sys [X]
S3 MBAMSwissArmy; \??\C:\Windows\system32\drivers\MBAMSwissArmy.sys [X]
U4 VBoxAswDrv; \??\C:\Nainstalovano\Avast\ng\vbox\VBoxAswDrv.sys [X]
==================== NetSvcs (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
==================== One Month Created files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2016-01-02 22:49 - 2016-01-02 22:49 - 00000000 ____D C:\FRST
2016-01-02 22:28 - 2016-01-02 22:28 - 00000000 _____ C:\Users\Paja\AppData\Local\{420565C7-551E-4DB4-A42D-D66A5D182EA7}
2016-01-02 22:28 - 2016-01-02 22:28 - 00000000 _____ C:\Users\Paja\AppData\Local\{260E69FE-667F-4EA6-AAA1-CDB82EE17888}
2016-01-02 18:23 - 2016-01-02 18:23 - 00000975 _____ C:\Users\Paja\Desktop\Install Kaspersky Internet Security version 16.0.0.614.lnk
2016-01-02 00:33 - 2015-12-29 01:00 - 319213865 _____ C:\Karel-Gott-2012-z-O2-areny-druhá-čast.webm
2016-01-02 00:32 - 2015-12-29 00:49 - 595946062 _____ C:\Karel Gott - O2 arena, 2012- první část.webm
2016-01-01 22:24 - 2016-01-01 22:25 - 21540440 _____ (Malwarebytes Corporation ) C:\Users\Paja\Downloads\mbam-setup-2.1.4.1018 (1).exe
2016-01-01 22:24 - 2016-01-01 22:24 - 21540440 _____ (Malwarebytes Corporation ) C:\Users\Paja\Downloads\mbam-setup-2.1.4.1018.exe
2016-01-01 22:12 - 2016-01-01 22:12 - 00000000 ____D C:\ProgramData\Kaspersky Lab Setup Files
2016-01-01 22:11 - 2016-01-01 22:12 - 01907824 _____ (Kaspersky Lab) C:\Users\Paja\Downloads\kis16.0.0.614en_8204 (1).exe
2016-01-01 22:11 - 2016-01-01 22:11 - 01907824 _____ (Kaspersky Lab) C:\Users\Paja\Downloads\kis16.0.0.614en_8204.exe
2015-12-31 18:11 - 2015-12-17 20:21 - 00579654 _____ C:\Na kolíčkách 2 2016.bmp
2015-12-29 23:27 - 2015-12-30 00:39 - 00000000 ____D C:\Anička proměny
2015-12-27 16:28 - 2016-01-01 22:43 - 00000000 ____D C:\ProgramData\TempMoudleSet
2015-12-27 16:28 - 2015-12-27 16:28 - 00000270 __RSH C:\ProgramData\ntuser.pol
2015-12-21 23:53 - 2015-12-17 20:18 - 01920054 _____ C:\Přání s textem 4 2016.bmp
2015-12-21 19:12 - 2015-12-21 19:15 - 00000000 ____D C:\dnes 21.12.2015
2015-12-20 22:24 - 2015-12-20 22:24 - 01920054 _____ C:\Přání s textem 3 2016_New.bmp
2015-12-20 22:23 - 2015-12-20 22:25 - 00003812 _____ C:\Přání s textem 3 2016_data.xml
2015-12-20 22:15 - 2015-12-17 20:18 - 01920054 _____ C:\Přání s textem 3 2016.bmp
2015-12-20 20:38 - 2015-12-20 20:50 - 00000000 ____D C:\fotky trhy výběr 2015
2015-12-20 20:13 - 2015-12-22 02:32 - 00000000 ____D C:\Vánoční trhy večer 2015
2015-12-18 17:55 - 2015-12-18 18:02 - 00000000 ____D C:\flash disk z.aloha dnes .18.12.2016
2015-12-18 01:39 - 2015-12-18 01:39 - 00322760 _____ (AVAST Software) C:\Windows\system32\aswBoot.exe
2015-12-18 01:39 - 2015-12-18 01:39 - 00043112 _____ (AVAST Software) C:\Windows\avastSS.scr
2015-12-17 21:42 - 2015-12-17 21:42 - 00002593 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office PowerPoint Viewer 2007.lnk
2015-12-17 21:42 - 2015-12-17 21:42 - 00000000 ____D C:\Program Files\Microsoft Office
2015-12-17 21:41 - 2015-12-17 21:41 - 00000000 ____D C:\Program Files\MSECache
2015-12-15 19:37 - 2015-12-15 20:01 - 00000000 ____D C:\Users\Paja\AppData\Roaming\iPhotoDraw
2015-12-15 19:37 - 2015-12-15 19:37 - 00001794 _____ C:\Users\Paja\Desktop\iPhotoDraw 2.0.lnk
2015-12-15 19:37 - 2015-12-15 19:37 - 00000000 ____D C:\Users\Paja\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\iPhotoDraw 2.0
2015-12-15 18:55 - 2015-12-15 18:55 - 00000000 ____D C:\Users\Paja\AppData\Local\kiwi.software.NET
2015-12-11 00:57 - 2015-12-11 22:52 - 00000000 ____D C:\Users\Paja\AppData\Roaming\Apple Computer
2015-12-11 00:57 - 2015-12-11 00:57 - 00001632 _____ C:\Users\Public\Desktop\iTunes.lnk
2015-12-11 00:57 - 2015-12-11 00:57 - 00000000 ____D C:\Users\Paja\AppData\Local\Apple Computer
2015-12-11 00:57 - 2015-12-11 00:57 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iTunes
2015-12-11 00:57 - 2015-12-11 00:57 - 00000000 ____D C:\ProgramData\Apple Computer
2015-12-11 00:57 - 2015-12-11 00:57 - 00000000 ____D C:\Program Files\iPod
2015-12-11 00:55 - 2015-12-11 00:55 - 00002519 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Apple Software Update.lnk
2015-12-11 00:55 - 2015-12-11 00:55 - 00000000 ____D C:\Users\Paja\AppData\Local\Apple
2015-12-11 00:55 - 2015-12-11 00:55 - 00000000 ____D C:\Program Files\Bonjour
2015-12-11 00:55 - 2015-12-11 00:55 - 00000000 ____D C:\Program Files\Apple Software Update
2015-12-11 00:54 - 2015-12-11 00:57 - 00000000 ____D C:\Program Files\Common Files\Apple
2015-12-11 00:54 - 2015-12-11 00:55 - 00000000 ____D C:\ProgramData\Apple
2015-12-07 15:23 - 2015-12-07 15:33 - 00000000 ____D C:\Vánoční trhy 2015
2015-12-05 22:23 - 2015-12-05 22:23 - 00000936 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore1d12fa330b3a975.job
2015-12-03 18:39 - 2015-12-03 18:39 - 00000000 ____D C:\Program Files\Common Files\AV
==================== One Month Modified files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2016-01-02 22:49 - 2009-07-14 03:37 - 00000000 ____D C:\Windows
2016-01-02 22:48 - 2014-04-11 15:32 - 00000000 ____D C:\Users\Paja\AppData\Roaming\Seznam.cz
2016-01-02 22:44 - 2014-04-11 16:05 - 00000384 _____ C:\Windows\Tasks\SlimDrivers Startup.job
2016-01-02 22:43 - 2015-09-22 16:11 - 00013464 _____ C:\Windows\system32\Drivers\SWDUMon.sys
2016-01-02 22:43 - 2014-04-11 15:21 - 00000936 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2016-01-02 22:43 - 2009-07-14 05:53 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2016-01-02 22:42 - 2014-04-11 15:21 - 00000936 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2016-01-02 21:57 - 2014-04-11 20:38 - 00000914 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job
2016-01-02 21:55 - 2009-07-14 05:34 - 00028352 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2016-01-02 21:55 - 2009-07-14 05:34 - 00028352 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2016-01-02 21:18 - 2014-04-11 21:02 - 00000000 ____D C:\Users\Paja\AppData\Roaming\uTorrent
2016-01-02 19:37 - 2010-11-21 02:16 - 00672046 _____ C:\Windows\system32\perfh005.dat
2016-01-02 19:37 - 2010-11-21 02:16 - 00142610 _____ C:\Windows\system32\perfc005.dat
2016-01-02 19:37 - 2010-11-20 22:01 - 01591750 _____ C:\Windows\system32\PerfStringBackup.INI
2016-01-02 19:37 - 2009-07-14 03:37 - 00000000 ____D C:\Windows\inf
2016-01-02 01:57 - 2015-11-22 22:54 - 00000000 ____D C:\Users\Paja\AppData\Roaming\vlc
2016-01-02 01:31 - 2015-02-21 21:07 - 00014011 _____ C:\Users\Paja\Desktop\Nový textový dokument (2).txt
2016-01-01 22:49 - 2014-04-11 15:15 - 00000000 ____D C:\Nainstalovano
2016-01-01 22:48 - 2014-06-24 14:04 - 00000000 ____D C:\Users\Paja\AppData\Local\CrashDumps
2015-12-31 22:42 - 2015-10-29 21:41 - 00000000 ____D C:\ProgramData\iSkysoft iMedia Converter Deluxe
2015-12-28 18:58 - 2014-04-11 20:38 - 00796864 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerApp.exe
2015-12-28 18:58 - 2014-04-11 20:38 - 00142528 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerCPLApp.cpl
2015-12-28 00:31 - 2014-09-13 09:03 - 00000000 ____D C:\s
2015-12-27 16:28 - 2015-09-22 16:30 - 00002331 _____ C:\Users\Public\Desktop\Google Chrome.lnk
2015-12-27 16:28 - 2015-09-19 13:42 - 00000000 ____D C:\Program Files\RayDld
2015-12-27 16:28 - 2014-06-06 10:22 - 00001098 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk
2015-12-27 16:28 - 2014-06-06 10:22 - 00001086 _____ C:\Users\Public\Desktop\Mozilla Firefox.lnk
2015-12-27 16:28 - 2014-04-11 15:40 - 00001078 _____ C:\Users\Public\Desktop\Opera.lnk
2015-12-27 16:28 - 2009-07-14 03:37 - 00000000 ___HD C:\Windows\system32\GroupPolicy
2015-12-26 10:51 - 2014-05-02 21:24 - 00000000 ____D C:\Program Files\Mozilla Maintenance Service
2015-12-20 01:04 - 2014-04-11 19:07 - 00000000 ____D C:\Users\Paja\AppData\Local\ElevatedDiagnostics
2015-12-20 00:03 - 2009-07-14 03:37 - 00000000 ____D C:\Windows\system32\NDF
2015-12-18 17:39 - 2014-04-11 15:21 - 00436360 _____ (AVAST Software) C:\Windows\system32\Drivers\aswsp.sys
2015-12-18 17:39 - 2014-04-11 15:21 - 00081168 _____ (AVAST Software) C:\Windows\system32\Drivers\aswmonflt.sys
2015-12-18 01:39 - 2014-04-27 17:18 - 00024016 _____ (AVAST Software) C:\Windows\system32\Drivers\aswHwid.sys
2015-12-18 01:39 - 2014-04-11 17:11 - 00020900 _____ C:\Users\Paja\Desktop\Nový textový dokument.txt
2015-12-18 01:39 - 2014-04-11 15:21 - 00794952 _____ (AVAST Software) C:\Windows\system32\Drivers\aswSnx.sys
2015-12-18 01:39 - 2014-04-11 15:21 - 00209432 _____ (AVAST Software) C:\Windows\system32\Drivers\aswVmm.sys
2015-12-18 01:39 - 2014-04-11 15:21 - 00117712 _____ (AVAST Software) C:\Windows\system32\Drivers\aswStm.sys
2015-12-18 01:39 - 2014-04-11 15:21 - 00081728 _____ (AVAST Software) C:\Windows\system32\Drivers\aswRdr2.sys
2015-12-18 01:39 - 2014-04-11 15:21 - 00049776 _____ (AVAST Software) C:\Windows\system32\Drivers\aswRvrt.sys
2015-12-15 22:58 - 2015-09-25 19:12 - 00000000 ____D C:\fotky poslat
2015-12-09 01:11 - 2014-04-11 19:52 - 00000000 ____D C:\Users\Paja\AppData\Roaming\AIMP3
2015-12-09 00:26 - 2014-05-05 21:41 - 00000000 ____D C:\Users\Paja\AppData\Roaming\dvdcss
2015-12-05 22:23 - 2015-09-19 22:34 - 00000936 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore1d0f322e751134a.job
==================== Files in the root of some directories =======
2014-08-08 23:17 - 2011-07-19 02:37 - 0003262 _____ () C:\Program Files\Falco.ico
2014-08-08 23:17 - 2011-07-19 03:05 - 0000046 _____ () C:\Program Files\Falco.url
2014-07-10 07:16 - 2014-07-10 07:16 - 2174976 _____ (Advanced Micro Devices Inc.) C:\Program Files\Common Files\atimpenc.dll
2014-04-17 22:50 - 2014-04-19 21:57 - 0087608 _____ () C:\Users\Paja\AppData\Roaming\inst.exe
2014-04-17 22:50 - 2014-04-19 21:57 - 0007887 _____ () C:\Users\Paja\AppData\Roaming\pcouffin.cat
2014-04-17 22:50 - 2014-04-19 21:57 - 0001144 _____ () C:\Users\Paja\AppData\Roaming\pcouffin.inf
2014-04-17 22:52 - 2014-04-19 21:57 - 0000034 _____ () C:\Users\Paja\AppData\Roaming\pcouffin.log
2014-04-17 22:50 - 2014-04-19 21:57 - 0047360 _____ (VSO Software) C:\Users\Paja\AppData\Roaming\pcouffin.sys
2014-04-17 22:52 - 2015-10-18 19:50 - 0000668 _____ () C:\Users\Paja\AppData\Roaming\vso_ts_preview.xml
2014-05-02 22:58 - 2014-05-02 22:58 - 0000001 _____ () C:\Users\Paja\AppData\Local\llftool.4.40.agreement
2015-10-15 21:09 - 2015-10-15 21:13 - 0033792 _____ () C:\Users\Paja\AppData\Local\Tempserver.exe
2016-01-02 22:28 - 2016-01-02 22:28 - 0000000 _____ () C:\Users\Paja\AppData\Local\{260E69FE-667F-4EA6-AAA1-CDB82EE17888}
2016-01-02 22:28 - 2016-01-02 22:28 - 0000000 _____ () C:\Users\Paja\AppData\Local\{420565C7-551E-4DB4-A42D-D66A5D182EA7}
2014-04-11 16:49 - 2014-04-11 16:49 - 0000000 ____H () C:\ProgramData\DP45977C.lfl
Some files in TEMP:
====================
C:\Users\Paja\AppData\Local\Temp\AskSLib.dll
C:\Users\Paja\AppData\Local\Temp\bdfilters.dll
C:\Users\Paja\AppData\Local\Temp\fp_pl_pfs_installer.exe
C:\Users\Paja\AppData\Local\Temp\FreemakeVideoConverterFull.exe
C:\Users\Paja\AppData\Local\Temp\FreemakeVideoDownloader_3.6.4.1.exe
C:\Users\Paja\AppData\Local\Temp\FreemakeVideoDownloader_3.6.4.3.exe
C:\Users\Paja\AppData\Local\Temp\FreeYouTubeDownload.exe
C:\Users\Paja\AppData\Local\Temp\hp_u_23828328.exe
C:\Users\Paja\AppData\Local\Temp\iupdate.exe
C:\Users\Paja\AppData\Local\Temp\jna1334869850114248042.dll
C:\Users\Paja\AppData\Local\Temp\KMP_3.2.0.0.exe
C:\Users\Paja\AppData\Local\Temp\listicka-partner-13415-1.1.2-offline.exe
C:\Users\Paja\AppData\Local\Temp\listicka.exe
C:\Users\Paja\AppData\Local\Temp\maucampoSetup.exe
C:\Users\Paja\AppData\Local\Temp\ose00000.exe
C:\Users\Paja\AppData\Local\Temp\OutpostSecuritySuiteProInstall_NoBase.exe
C:\Users\Paja\AppData\Local\Temp\ReimagePackage.exe
C:\Users\Paja\AppData\Local\Temp\SkypeSetup.exe
C:\Users\Paja\AppData\Local\Temp\sp-downloader.exe
C:\Users\Paja\AppData\Local\Temp\SpeedUpMyComputer.exe
C:\Users\Paja\AppData\Local\Temp\tmd_34011571.exe
C:\Users\Paja\AppData\Local\Temp\tmd_34012617.exe
C:\Users\Paja\AppData\Local\Temp\tmd_34013608.exe
C:\Users\Paja\AppData\Local\Temp\tmd_34014889.exe
C:\Users\Paja\AppData\Local\Temp\tmd_34016271.exe
C:\Users\Paja\AppData\Local\Temp\tmd_34016886.exe
C:\Users\Paja\AppData\Local\Temp\tmd_34017186.exe
C:\Users\Paja\AppData\Local\Temp\tmd_34017419.exe
C:\Users\Paja\AppData\Local\Temp\tmd_34017597.exe
C:\Users\Paja\AppData\Local\Temp\tmd_34017755.exe
C:\Users\Paja\AppData\Local\Temp\tmd_34018251.exe
C:\Users\Paja\AppData\Local\Temp\tmd_34018466.exe
C:\Users\Paja\AppData\Local\Temp\tmd_34018741.exe
C:\Users\Paja\AppData\Local\Temp\WinUpdat.exe
C:\Users\Paja\AppData\Local\Temp\YandexWorking.exe
C:\Users\Paja\AppData\Local\Temp\{E638ABC1-0067-474b-A379-87CFE81E7848}.exe
C:\Users\Paja\AppData\Local\Temp\~ACE3.exe
C:\Users\Paja\AppData\Local\Temp\~D4EB.exe
==================== Bamital & volsnap =================
(There is no automatic fix for files that do not pass verification.)
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\system32\winlogon.exe => MD5 is legit
C:\Windows\system32\wininit.exe => File is digitally signed
C:\Windows\system32\svchost.exe => File is digitally signed
C:\Windows\system32\services.exe
[2015-05-13 14:28] - [2015-04-13 04:19] - 0259072 ____A (Microsoft Corporation) 0780A42DBD7D9969F9BF4A19AA4285B5
C:\Windows\system32\User32.dll => File is digitally signed
C:\Windows\system32\userinit.exe => File is digitally signed
C:\Windows\system32\rpcss.dll => File is digitally signed
C:\Windows\system32\dnsapi.dll => File is digitally signed
C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed
LastRegBack: 2015-12-30 20:38
==================== End of FRST.txt ============================
