Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version:27-01-2016
Ran by kristian (administrator) on KRISTIAN-PC (30-01-2016 17:36:01)
Running from C:\Users\kristian\Desktop
Loaded Profiles: kristian (Available Profiles: kristian)
Platform: Microsoft Windows 7 Home Premium Service Pack 1 (X86) Language: Slovenčina (Slovensko)
Internet Explorer Version 11 (Default browser: Chrome)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool:
http://www.geekstogo.com/forum/topic/33 ... scan-tool/
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(Avira Operations GmbH & Co. KG) C:\Program Files\Avira\Antivirus\sched.exe
(Google Inc.) C:\Program Files\Google\Update\1.3.29.1\GoogleCrashHandler.exe
(Avira Operations GmbH & Co. KG) C:\Program Files\Avira\Antivirus\avguard.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NetService\NvNetworkService.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamService.exe
(Avira Operations GmbH & Co. KG) C:\Program Files\Avira\Launcher\Avira.ServiceHost.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Update Core\NvBackend.exe
(Adobe Systems Incorporated) C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe
(Avira Operations GmbH & Co. KG) C:\Program Files\Avira\Antivirus\avgnt.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe
(Oracle Corporation) C:\Program Files\Common Files\Java\Java Update\jusched.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
(Google) C:\Program Files\Google\Drive\googledrivesync.exe
(WinZip Computing LP) C:\Program Files\WinZip\WZQKPICK.EXE
(Piriform Ltd) C:\Program Files\CCleaner\CCleaner.exe
() C:\Users\kristian\AppData\Roaming\Seznam.cz\bin\szndesktop.exe
(Google) C:\Program Files\Google\Drive\googledrivesync.exe
(Microsoft Corporation) C:\Windows\System32\GWX\GWX.exe
(Avira Operations GmbH & Co. KG) C:\Program Files\Avira\Launcher\Avira.Systray.exe
(Avira Operations GmbH & Co. KG) C:\Program Files\Avira\Antivirus\avshadow.exe
(Disc Soft Ltd) C:\Program Files\DAEMON Tools Lite\DiscSoftBusService.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamNetworkService.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamUserAgent.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(NVIDIA) C:\Program Files\NVIDIA Corporation\NVIDIA GeForce Experience\GFExperience.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Avira Operations GmbH & Co. KG) C:\Program Files\Avira\Antivirus\avcenter.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
==================== Registry (Whitelisted) ===========================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [NvBackend] => C:\Program Files\NVIDIA Corporation\Update Core\NvBackend.exe [2787264 2016-01-12] (NVIDIA Corporation)
HKLM\...\Run: [ShadowPlay] => "C:\Windows\system32\rundll32.exe" C:\Windows\system32\nvspcap.dll,ShadowPlayOnSystemStart
HKLM\...\Run: [AdobeAAMUpdater-1.0] => C:\Program Files\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [446392 2012-04-04] (Adobe Systems Incorporated)
HKLM\...\Run: [SwitchBoard] => C:\Program Files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [517096 2010-02-19] (Adobe Systems Incorporated)
HKLM\...\Run: [AdobeCS6ServiceManager] => C:\Program Files\Common Files\Adobe\CS6ServiceManager\CS6ServiceManager.exe [1073312 2012-03-09] (Adobe Systems Incorporated)
HKLM\...\Run: [seznam-listicka-distribuce] => C:\Program Files\Seznam.cz\distribution\szninstall.exe [1062472 2013-05-16] ()
HKLM\...\Run: [Adobe ARM] => C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [1085656 2015-12-13] (Adobe Systems Incorporated)
HKLM\...\Run: [Avira SystrayStartTrigger] => C:\Program Files\Avira\Launcher\Avira.SystrayStartTrigger.exe [66320 2015-12-08] (Avira Operations GmbH & Co. KG)
HKLM\...\Run: [avgnt] => C:\Program Files\Avira\Antivirus\avgnt.exe [803200 2015-12-03] (Avira Operations GmbH & Co. KG)
HKLM\...\Run: [EasySettingBox] => C:\Program Files\Samsung\Easy Setting Box\EasySettingBox.exe [463360 2014-06-18] ()
HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe [11680400 2012-10-26] (Realtek Semiconductor)
HKLM\...\Run: [SunJavaUpdateSched] => C:\Program Files\Common Files\Java\Java Update\jusched.exe [596528 2015-12-22] (Oracle Corporation)
HKU\S-1-5-21-2995324089-3222424015-723345418-1000\...\Run: [CCleaner Monitoring] => C:\Program Files\CCleaner\CCleaner.exe [6628056 2016-01-15] (Piriform Ltd)
HKU\S-1-5-21-2995324089-3222424015-723345418-1000\...\Run: [DAEMON Tools Lite Automount] => C:\Program Files\DAEMON Tools Lite\DTAgent.exe [3576664 2015-06-18] (Disc Soft Ltd)
HKU\S-1-5-21-2995324089-3222424015-723345418-1000\...\Run: [AdobeBridge] => [X]
HKU\S-1-5-21-2995324089-3222424015-723345418-1000\...\Run: [GoogleDriveSync] => C:\Program Files\Google\Drive\googledrivesync.exe [22790776 2015-11-04] (Google)
HKU\S-1-5-21-2995324089-3222424015-723345418-1000\...\Run: [cz.seznam.software.autoupdate] => C:\Users\kristian\AppData\Roaming\Seznam.cz\szninstall.exe [1062472 2013-05-16] ()
HKU\S-1-5-21-2995324089-3222424015-723345418-1000\...\Run: [cz.seznam.software.szndesktop] => C:\Users\kristian\AppData\Roaming\Seznam.cz\bin\wszndesktop.exe [103080 2015-05-26] ()
HKU\S-1-5-21-2995324089-3222424015-723345418-1000\...\MountPoints2: {b26f06ee-3b49-11e5-8509-806e6f6e6963} - E:\setup.exe
HKU\S-1-5-18\...\RunOnce: [SPReview] => C:\Windows\System32\SPReview\SPReview.exe [280576 2015-08-05] (Microsoft Corporation)
ShellIconOverlayIdentifiers: [ GoogleDriveBlacklisted] -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D42} => C:\Program Files\Google\Drive\googledrivesync32.dll [2015-11-04] (Google)
ShellIconOverlayIdentifiers: [ GoogleDriveSynced] -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D40} => C:\Program Files\Google\Drive\googledrivesync32.dll [2015-11-04] (Google)
ShellIconOverlayIdentifiers: [ GoogleDriveSyncing] -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D41} => C:\Program Files\Google\Drive\googledrivesync32.dll [2015-11-04] (Google)
ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => No File
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\WinZip Quick Pick.lnk [2015-08-05]
ShortcutTarget: WinZip Quick Pick.lnk -> C:\Program Files\WinZip\WZQKPICK.EXE (WinZip Computing LP)
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
Tcpip\Parameters: [DhcpNameServer] 192.168.100.1
Tcpip\..\Interfaces\{A819C8DE-58DE-4BEE-8A88-D6B071AB8674}: [DhcpNameServer] 192.168.100.1
Internet Explorer:
==================
BHO: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre1.8.0_71\bin\ssv.dll [2016-01-23] (Oracle Corporation)
BHO: AviraBrowserSafety.BrowserSafety -> {c3c77255-42c0-499f-b664-6e981a0b1647} -> C:\Windows\system32\mscoree.dll [2010-11-05] (Microsoft Corporation)
BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre1.8.0_71\bin\jp2ssv.dll [2016-01-23] (Oracle Corporation)
FireFox:
========
FF ProfilePath: C:\Users\kristian\AppData\Roaming\Mozilla\Firefox\Profiles\gsvvxlqr.default
FF Plugin: @java.com/DTPlugin,version=11.71.2 -> C:\Program Files\Java\jre1.8.0_71\bin\dtplugin\npDeployJava1.dll [2016-01-23] (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=11.71.2 -> C:\Program Files\Java\jre1.8.0_71\bin\plugin2\npjp2.dll [2016-01-23] (Oracle Corporation)
FF Plugin: @nvidia.com/3DVision -> C:\Program Files\NVIDIA Corporation\3D Vision\npnv3dv.dll [2015-12-16] (NVIDIA Corporation)
FF Plugin: @nvidia.com/3DVisionStreaming -> C:\Program Files\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll [2015-12-16] (NVIDIA Corporation)
FF Plugin: @tools.google.com/Google Update;version=3 -> C:\Program Files\Google\Update\1.3.29.1\npGoogleUpdate3.dll [2015-12-04] (Google Inc.)
FF Plugin: @tools.google.com/Google Update;version=9 -> C:\Program Files\Google\Update\1.3.29.1\npGoogleUpdate3.dll [2015-12-04] (Google Inc.)
FF Plugin: @videolan.org/vlc,version=2.2.1 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2015-04-13] (VideoLAN)
FF Plugin: Adobe Reader -> C:\Program Files\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll [2015-12-17] (Adobe Systems Inc.)
FF Extension: Avira Browser Safety - C:\Users\kristian\AppData\Roaming\Mozilla\Firefox\Profiles\gsvvxlqr.default\Extensions\
abs@avira.com [2016-01-18]
FF Extension: Avira SafeSearch Plus - C:\Users\kristian\AppData\Roaming\Mozilla\Firefox\Profiles\gsvvxlqr.default\Extensions\
safesearchplus2@avira.com [2016-01-18]
FF Extension: Seznam lištička - C:\Users\kristian\AppData\Roaming\Mozilla\Firefox\Profiles\gsvvxlqr.default\Extensions\{ea614400-e918-4741-9a97-7a972ff7c30b} [2015-12-12]
FF HKU\S-1-5-21-2995324089-3222424015-723345418-1000\...\SeaMonkey\Extensions: [
mozilla_cc2@internetdownloadmanager.com] - C:\Program Files\Internet Download Manager\idmmzcc2.xpi => not found
Chrome:
=======
CHR StartupUrls: Default -> "hxxp://
www.google.com/"
CHR DefaultSearchURL: Default -> hxxps://search.avira.net/#web/result?source=omnibar&q={searchTerms}
CHR DefaultSearchKeyword: Default -> Avira
CHR DefaultSuggestURL: Default -> hxxps://search.avira.net/suggestions?q={searchTerms}&li=ff&hl=en
CHR Profile: C:\Users\kristian\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (Prezentácie Google) - C:\Users\kristian\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2015-08-05]
CHR Extension: (Dokumenty Google) - C:\Users\kristian\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2015-08-05]
CHR Extension: (Disk Google) - C:\Users\kristian\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2015-10-21]
CHR Extension: (App Launcher for Messenger) - C:\Users\kristian\AppData\Local\Google\Chrome\User Data\Default\Extensions\bllmngcdibgbgjnginpehneeofhbmdjm [2016-01-18]
CHR Extension: (YouTube) - C:\Users\kristian\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2015-09-24]
CHR Extension: (Google Search) - C:\Users\kristian\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2015-10-27]
CHR Extension: (Tabuľky Google) - C:\Users\kristian\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2015-08-05]
CHR Extension: (Avira Browser Safety) - C:\Users\kristian\AppData\Local\Google\Chrome\User Data\Default\Extensions\flliilndjeohchalpbbcdekjklbdgfkk [2016-01-28]
CHR Extension: (Dokumenty Google v režime offline) - C:\Users\kristian\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2015-11-18]
CHR Extension: (AdBlock) - C:\Users\kristian\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom [2016-01-28]
CHR Extension: (Avira SafeSearch Plus) - C:\Users\kristian\AppData\Local\Google\Chrome\User Data\Default\Extensions\ipmkfpcnmccejididiaagpgchgjfajgp [2016-01-19]
CHR Extension: (Application Launcher for Drive (by Google)) - C:\Users\kristian\AppData\Local\Google\Chrome\User Data\Default\Extensions\lmjegmlicamnimmfhcmpkclmigmmcbeh [2015-11-20]
CHR Extension: (Platby Internetového obchodu Chrome) - C:\Users\kristian\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2015-08-05]
CHR Extension: (Gmail) - C:\Users\kristian\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2015-08-05]
CHR HKLM\...\Chrome\Extension: [flliilndjeohchalpbbcdekjklbdgfkk] - hxxps://clients2.google.com/service/update2/crx
CHR HKLM\...\Chrome\Extension: [ipmkfpcnmccejididiaagpgchgjfajgp] - hxxps://clients2.google.com/service/update2/crx
CHR HKU\S-1-5-21-2995324089-3222424015-723345418-1000\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [lmjegmlicamnimmfhcmpkclmigmmcbeh] - hxxps://clients2.google.com/service/update2/crx
==================== Services (Whitelisted) ========================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
S2 AntiVirMailService; C:\Program Files\Avira\Antivirus\avmailc7.exe [948392 2015-12-03] (Avira Operations GmbH & Co. KG)
R2 AntiVirSchedulerService; C:\Program Files\Avira\Antivirus\sched.exe [466408 2015-12-03] (Avira Operations GmbH & Co. KG)
R2 AntiVirService; C:\Program Files\Avira\Antivirus\avguard.exe [466408 2015-12-03] (Avira Operations GmbH & Co. KG)
S2 AntiVirWebService; C:\Program Files\Avira\Antivirus\avwebg7.exe [1418560 2015-12-03] (Avira Operations GmbH & Co. KG)
R2 Avira.ServiceHost; C:\Program Files\Avira\Launcher\Avira.ServiceHost.exe [251160 2015-12-08] (Avira Operations GmbH & Co. KG)
R3 Disc Soft Lite Bus Service; C:\Program Files\DAEMON Tools Lite\DiscSoftBusService.exe [1034584 2015-06-18] (Disc Soft Ltd)
S3 fussvc; C:\Program Files\Windows Kits\8.1\App Certification Kit\fussvc.exe [140800 2014-02-19] (Microsoft Corporation) [File not signed]
R2 GfExperienceService; C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe [929728 2016-01-12] (NVIDIA Corporation)
R2 NvNetworkService; C:\Program Files\NVIDIA Corporation\NetService\NvNetworkService.exe [1879488 2016-01-12] (NVIDIA Corporation)
R3 NvStreamNetworkSvc; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamNetworkService.exe [5178816 2016-01-12] (NVIDIA Corporation)
R2 NvStreamSvc; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamService.exe [3996608 2016-01-12] (NVIDIA Corporation)
S3 SwitchBoard; C:\Program Files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [517096 2010-02-19] (Adobe Systems Incorporated) [File not signed]
S3 Te.Service; C:\Program Files\Windows Kits\8.1\Testing\Runtimes\TAEF\Wex.Services.exe [91136 2013-08-21] (Microsoft Corporation) [File not signed]
S3 VSStandardCollectorService140; C:\Program Files\Microsoft Visual Studio 14.0\Team Tools\DiagnosticsHub\Collector\StandardCollector.Service.exe [45800 2015-07-06] (Microsoft Corporation)
S3 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [680960 2013-05-27] (Microsoft Corporation)
===================== Drivers (Whitelisted) ==========================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [106968 2015-12-03] (Avira Operations GmbH & Co. KG)
R1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [136272 2015-12-03] (Avira Operations GmbH & Co. KG)
R1 avkmgr; C:\Windows\System32\DRIVERS\avkmgr.sys [37896 2015-12-03] (Avira Operations GmbH & Co. KG)
R2 avnetflt; C:\Windows\System32\DRIVERS\avnetflt.sys [55456 2015-12-03] (Avira Operations GmbH & Co. KG)
R3 dtlitescsibus; C:\Windows\System32\DRIVERS\dtlitescsibus.sys [25016 2015-08-14] (Disc Soft Ltd)
R3 NvStreamKms; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys [25536 2016-01-12] (NVIDIA Corporation)
R3 nvvad_WaveExtensible; C:\Windows\System32\drivers\nvvad32v.sys [42128 2015-12-18] (NVIDIA Corporation)
R1 ssmdrv; C:\Windows\System32\DRIVERS\ssmdrv.sys [31848 2015-12-03] (Avira Operations GmbH & Co. KG)
S3 cpuz137; \??\C:\Program Files\CPUID\PC Wizard 2013\pcwiz_x32.sys [X]
==================== NetSvcs (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
==================== One Month Created files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2016-01-30 17:36 - 2016-01-30 17:36 - 00017147 _____ C:\Users\kristian\Desktop\FRST.txt
2016-01-30 17:34 - 2016-01-30 17:36 - 00000000 ____D C:\FRST
2016-01-30 17:31 - 2016-01-30 17:31 - 01721856 _____ (Farbar) C:\Users\kristian\Desktop\FRST.exe
2016-01-30 11:11 - 2016-01-30 11:11 - 00000000 ____D C:\Users\kristian\AppData\Local\ElevatedDiagnostics
2016-01-30 10:47 - 2016-01-30 11:12 - 00197690 _____ C:\Windows\ntbtlog.txt
2016-01-30 10:38 - 2016-01-30 10:39 - 22908888 _____ (Malwarebytes ) C:\Users\kristian\Downloads\mbam-setup-2.2.0.1024 (1).exe
2016-01-30 09:59 - 2016-01-30 10:00 - 02065944 _____ (BitTorrent Inc.) C:\Users\kristian\Downloads\uTorrent.exe
2016-01-28 17:46 - 2016-01-28 17:46 - 00000965 _____ C:\Users\Public\Desktop\CCleaner.lnk
2016-01-28 17:45 - 2016-01-28 17:46 - 06826984 _____ (Piriform Ltd) C:\Users\kristian\Downloads\ccsetup514pro.exe
2016-01-27 12:24 - 2016-01-27 12:24 - 00000000 ____D C:\ProgramData\Malwarebytes
2016-01-25 12:59 - 2016-01-25 12:59 - 00000000 ____D C:\Games
2016-01-25 12:58 - 2016-01-25 12:58 - 05124704 _____ (Wargaming.net ) C:\Users\kristian\Downloads\WoT_internet_install_eu.exe
2016-01-23 18:29 - 2016-01-23 18:29 - 00000000 ____D C:\Program Files\Common Files\Java
2016-01-23 18:21 - 2016-01-23 18:21 - 05026008 _____ (For Intel powered by System Requirements Lab) C:\Users\kristian\Downloads\Intel Detection.exe
2016-01-23 13:26 - 2016-01-23 16:02 - 1682085166 _____ C:\Users\kristian\Downloads\Scouts-Guide-to-the-Zombie-Apocalypse-CZ-Dabing-Komedie---Horor,-USA,-2015...http---ulozto.cz--partner=154291.avi
2016-01-22 20:12 - 2016-01-22 20:12 - 00000000 ____D C:\Windows\system32\RTCOM
2016-01-22 20:11 - 2012-10-30 10:59 - 03340880 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\Drivers\RTKVHDA.sys
2016-01-22 20:11 - 2012-10-30 09:43 - 00369117 _____ C:\Windows\system32\Drivers\RTAIODAT.DAT
2016-01-22 20:11 - 2012-10-29 07:41 - 09378304 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\RCoRes.dat
2016-01-22 20:11 - 2012-10-25 07:45 - 00097424 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\RtkCoInstII.dll
2016-01-22 20:11 - 2012-10-23 04:30 - 03219600 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\RtkAPO.dll
2016-01-22 20:11 - 2012-10-03 10:57 - 00726656 _____ (Sony Corporation) C:\Windows\system32\SFSS_APO.dll
2016-01-22 20:11 - 2012-09-24 09:32 - 07370104 _____ (Waves Audio Ltd.) C:\Windows\system32\MaxxAudioRealtek.dll
2016-01-22 20:11 - 2012-09-24 09:32 - 01801592 _____ (Waves Audio Ltd.) C:\Windows\system32\WavesGUILib.dll
2016-01-22 20:11 - 2012-09-20 15:44 - 01267064 _____ (Waves Audio Ltd.) C:\Windows\system32\MaxxAudioRealtek2.dll
2016-01-22 20:11 - 2012-09-19 17:59 - 00742264 _____ (Waves Audio Ltd.) C:\Windows\system32\MaxxAudioAPOShell.dll
2016-01-22 20:11 - 2012-09-12 02:51 - 02486416 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\RtkPgExt.dll
2016-01-22 20:11 - 2012-09-09 07:33 - 01929080 _____ (Waves Audio Ltd.) C:\Windows\system32\MaxxAudioEQ.dll
2016-01-22 20:11 - 2012-08-31 12:17 - 07162128 _____ (Dolby Laboratories) C:\Windows\system32\R4EEP32A.dll
2016-01-22 20:11 - 2012-08-31 12:17 - 00352016 _____ (Dolby Laboratories) C:\Windows\system32\R4EED32A.dll
2016-01-22 20:11 - 2012-08-31 12:17 - 00106768 _____ (Dolby Laboratories) C:\Windows\system32\R4EEL32A.dll
2016-01-22 20:11 - 2012-08-31 12:17 - 00091920 _____ (Dolby Laboratories) C:\Windows\system32\R4EEA32A.dll
2016-01-22 20:11 - 2012-08-31 12:17 - 00062224 _____ (Dolby Laboratories) C:\Windows\system32\R4EEG32A.dll
2016-01-22 20:11 - 2012-08-21 07:51 - 00658064 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\RtkApoApi.dll
2016-01-22 20:11 - 2012-08-13 11:06 - 01501840 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\RTSndMgr.cpl
2016-01-22 20:11 - 2012-07-15 14:13 - 00350072 _____ (Waves Audio Ltd.) C:\Windows\system32\MaxxAudioAPO30.dll
2016-01-22 20:11 - 2012-07-15 14:13 - 00349048 _____ (Waves Audio Ltd.) C:\Windows\system32\MaxxVolumeSDAPO.dll
2016-01-22 20:11 - 2012-01-30 04:42 - 00819648 _____ (TOSHIBA Corporation) C:\Windows\system32\tadefxapo2.dll
2016-01-22 20:11 - 2012-01-10 03:20 - 00058264 _____ (TOSHIBA CORPORATION.) C:\Windows\system32\TepeqAPO.dll
2016-01-22 20:11 - 2011-11-22 09:28 - 00013416 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\RtkCoLDR.dll
2016-01-22 20:11 - 2011-09-02 07:21 - 00214368 _____ (Synopsys, Inc.) C:\Windows\system32\SFNHK.dll
2016-01-22 20:11 - 2011-09-02 07:21 - 00074080 _____ (Synopsys, Inc.) C:\Windows\system32\SFCOM.dll
2016-01-22 20:11 - 2011-09-02 07:21 - 00068960 _____ (Synopsys, Inc.) C:\Windows\system32\SFAPO.dll
2016-01-22 20:11 - 2011-03-17 05:16 - 01379760 _____ (TOSHIBA Corporation) C:\Windows\system32\tosade.dll
2016-01-22 20:11 - 2011-03-07 10:03 - 00134584 _____ (TOSHIBA Corporation) C:\Windows\system32\tadefxapo.dll
2016-01-22 20:11 - 2010-11-08 00:31 - 00359768 _____ (Dolby Laboratories, Inc.) C:\Windows\system32\RTEEP32A.dll
2016-01-22 20:11 - 2010-11-08 00:31 - 00295768 _____ (Dolby Laboratories, Inc.) C:\Windows\system32\RP3DHT32.dll
2016-01-22 20:11 - 2010-11-08 00:31 - 00295768 _____ (Dolby Laboratories, Inc.) C:\Windows\system32\RP3DAA32.dll
2016-01-22 20:11 - 2010-11-08 00:31 - 00170840 _____ (Dolby Laboratories, Inc.) C:\Windows\system32\RTEED32A.dll
2016-01-22 20:11 - 2010-11-08 00:31 - 00078680 _____ (Dolby Laboratories, Inc.) C:\Windows\system32\RTEEL32A.dll
2016-01-22 20:11 - 2010-11-08 00:31 - 00064856 _____ (Dolby Laboratories, Inc.) C:\Windows\system32\RTEEG32A.dll
2016-01-22 20:11 - 2010-09-27 02:34 - 00232792 _____ (Waves Audio Ltd.) C:\Windows\system32\MaxxAudioAPO20.dll
2016-01-22 20:11 - 2009-12-04 08:43 - 00132368 _____ (Waves Audio Ltd.) C:\Windows\system32\MaxxAudioAPO.dll
2016-01-22 20:11 - 2009-11-24 02:55 - 00345328 _____ (SRS Labs, Inc.) C:\Windows\system32\SRSTSXT.dll
2016-01-22 20:11 - 2009-11-24 02:55 - 00185584 _____ (SRS Labs, Inc.) C:\Windows\system32\SRSTSHD.dll
2016-01-22 20:11 - 2009-11-24 02:55 - 00173296 _____ (SRS Labs, Inc.) C:\Windows\system32\SRSHP360.dll
2016-01-22 20:11 - 2009-11-24 02:55 - 00140528 _____ (SRS Labs, Inc.) C:\Windows\system32\SRSWOW.dll
2016-01-22 20:11 - 2009-11-18 11:42 - 01783056 _____ (Waves Audio Ltd.) C:\Windows\system32\WavesLib.dll
2016-01-22 20:10 - 2012-10-29 09:34 - 02357344 _____ (Fortemedia Corporation) C:\Windows\system32\FMAPO.dll
2016-01-22 20:10 - 2012-10-02 07:39 - 00426952 _____ (DTS) C:\Windows\system32\DTSU2PLFX32.dll
2016-01-22 20:10 - 2012-10-02 07:39 - 00402888 _____ (DTS) C:\Windows\system32\DTSU2PGFX32.dll
2016-01-22 20:10 - 2012-10-02 07:39 - 00346056 _____ (DTS) C:\Windows\system32\DTSU2PREC32.dll
2016-01-22 20:10 - 2012-06-20 10:26 - 00090624 _____ (Real Sound Lab SIA) C:\Windows\system32\CONEQMSAPOGUILibrary.dll
2016-01-22 20:10 - 2012-03-08 04:47 - 00176736 _____ (Andrea Electronics Corporation) C:\Windows\system32\AERTACap.dll
2016-01-22 20:10 - 2012-03-08 04:47 - 00095840 _____ (Andrea Electronics Corporation) C:\Windows\system32\AERTARen.dll
2016-01-22 20:10 - 2011-08-23 10:00 - 00357712 _____ (Knowles Acoustics ) C:\Windows\system32\KAAPORT.dll
2016-01-22 20:10 - 2011-05-31 02:42 - 01509480 _____ (DTS) C:\Windows\system32\DTSS2SpeakerDLL.dll
2016-01-22 20:10 - 2011-05-31 02:42 - 01292904 _____ (DTS) C:\Windows\system32\DTSS2HeadphoneDLL.dll
2016-01-22 20:10 - 2011-05-31 02:42 - 01220200 _____ (DTS) C:\Windows\system32\DTSBoostDLL.dll
2016-01-22 20:10 - 2011-05-31 02:42 - 00654952 _____ (DTS) C:\Windows\system32\DTSBassEnhancementDLL.dll
2016-01-22 20:10 - 2011-05-31 02:42 - 00631400 _____ (DTS) C:\Windows\system32\DTSSymmetryDLL.dll
2016-01-22 20:10 - 2011-05-31 02:42 - 00601704 _____ (DTS) C:\Windows\system32\DTSVoiceClarityDLL.dll
2016-01-22 20:10 - 2011-05-31 02:42 - 00458344 _____ (DTS) C:\Windows\system32\DTSNeoPCDLL.dll
2016-01-22 20:10 - 2011-05-31 02:42 - 00389736 _____ (DTS) C:\Windows\system32\DTSGainCompensatorDLL.dll
2016-01-22 20:10 - 2011-05-31 02:42 - 00375400 _____ (DTS) C:\Windows\system32\DTSLimiterDLL.dll
2016-01-22 20:10 - 2011-05-31 02:42 - 00218728 _____ (DTS) C:\Windows\system32\DTSGFXAPONS.dll
2016-01-22 20:10 - 2011-05-31 02:42 - 00218728 _____ (DTS) C:\Windows\system32\DTSGFXAPO.dll
2016-01-22 20:10 - 2011-05-31 02:42 - 00218216 _____ (DTS) C:\Windows\system32\DTSLFXAPO.dll
2016-01-22 19:53 - 2016-01-22 19:54 - 12771448 _____ C:\Users\kristian\Downloads\pc-wizard_2014.2.13-setup.exe
2016-01-22 19:46 - 2016-01-22 19:46 - 00000000 ____D C:\Users\kristian\AppData\Roaming\EasySettingBox
2016-01-22 19:44 - 2016-01-22 19:44 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Samsung
2016-01-22 19:44 - 2016-01-22 19:44 - 00000000 ____D C:\Program Files\Samsung
2016-01-22 19:41 - 2016-01-22 19:41 - 00000000 ____D C:\Program Files\MonitorDriver
2016-01-22 19:30 - 2015-12-18 07:11 - 00042128 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvvad32v.sys
2016-01-22 19:30 - 2015-12-18 07:10 - 00090768 _____ (NVIDIA Corporation) C:\Windows\system32\nvaudcap32v.dll
2016-01-21 12:29 - 2016-01-21 12:29 - 00350904 _____ C:\Users\kristian\Downloads\redcoast.vlt
2016-01-21 12:22 - 2016-01-25 10:14 - 00000000 ____D C:\Users\kristian\AppData\Roaming\vlc
2016-01-21 12:18 - 2016-01-21 12:21 - 28849904 _____ C:\Users\kristian\Downloads\vlc-2.2.1-win32.exe
2016-01-21 12:12 - 2016-01-21 12:17 - 00000000 ____D C:\ProgramData\Free Online TV
2016-01-21 12:09 - 2016-01-21 12:11 - 27638208 _____ (NETGATE Technologies s.r.o. ) C:\Users\kristian\Downloads\ft-setup.exe
2016-01-20 22:02 - 2016-01-20 22:04 - 22908888 _____ (Malwarebytes ) C:\Users\kristian\Downloads\mbam-setup-2.2.0.1024.exe
2016-01-18 18:10 - 2016-01-18 18:10 - 00000000 ____D C:\Users\kristian\AppData\Roaming\Avira
2016-01-18 17:50 - 2015-12-03 15:25 - 00031848 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\ssmdrv.sys
2016-01-18 17:50 - 2015-12-03 15:24 - 00136272 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avipbb.sys
2016-01-18 17:50 - 2015-12-03 15:24 - 00106968 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avgntflt.sys
2016-01-18 17:50 - 2015-12-03 15:24 - 00055456 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avnetflt.sys
2016-01-18 17:50 - 2015-12-03 15:24 - 00037896 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avkmgr.sys
2016-01-18 17:19 - 2016-01-18 17:53 - 00000000 ____D C:\Program Files\Avira
2016-01-18 17:19 - 2016-01-18 17:52 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avira
2016-01-18 17:19 - 2016-01-18 17:50 - 00000000 ____D C:\ProgramData\Avira
2016-01-18 17:18 - 2016-01-18 17:19 - 04638208 _____ (Avira Operations GmbH & Co. KG) C:\Users\kristian\Downloads\avira_en_av_5698e3044d5d9__adw.exe
2016-01-18 17:01 - 2016-01-18 17:01 - 00000000 ____D C:\ProgramData\Kaspersky Lab Setup Files
2016-01-18 12:38 - 2016-01-18 12:55 - 00000000 ____D C:\ProgramData\EPS
2016-01-18 12:38 - 2016-01-18 12:38 - 00000000 ____D C:\Program Files\Didsoft
2016-01-18 12:37 - 2016-01-18 12:37 - 02503365 _____ (hxxp://
www.didsoft.com ) C:\Users\kristian\Downloads\EPS_setup.exe
2016-01-18 11:28 - 2016-01-18 11:34 - 00000000 ____D C:\Users\kristian\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Aplikácie Chrome
2016-01-18 11:27 - 2016-01-18 11:27 - 00002255 _____ C:\Users\kristian\Desktop\Spúšťač aplikácií Chrome.lnk
2016-01-18 11:27 - 2016-01-18 11:27 - 00000000 ____D C:\Users\kristian\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Google Chrome
2016-01-14 22:00 - 2016-01-14 22:00 - 00000000 ____D C:\ProgramData\Steam
2016-01-14 19:48 - 2016-01-14 19:48 - 09758097 _____ C:\Users\kristian\Downloads\crack.rar
2016-01-14 16:03 - 2016-01-14 16:45 - 468242732 _____ C:\Users\kristian\Downloads\rome 2 TW update 1 az 4 RELOADED.rar
2016-01-14 15:52 - 2016-01-14 20:32 - 00000000 ____D C:\Program Files\Total War ROME II
2016-01-13 19:22 - 2016-01-13 19:22 - 00000000 ____D C:\Users\kristian\AppData\Roaming\The Creative Assembly
2016-01-11 19:35 - 2016-01-11 19:35 - 00063950 _____ C:\Users\kristian\Downloads\[CzT]Shogun_2_Total_War_CZ_FLT_vse_plne_funkcni_.torrent
2016-01-10 19:15 - 2016-01-10 19:15 - 00041993 _____ C:\Users\kristian\Downloads\menza1.rar
2016-01-10 17:34 - 2016-01-10 17:34 - 00480176 _____ C:\Users\kristian\Desktop\Bez názvu-1.psd
2016-01-07 18:26 - 2016-01-07 18:26 - 00000000 ____D C:\Users\kristian\AppData\Roaming\MAGIX
2016-01-07 18:26 - 2016-01-07 18:26 - 00000000 ____D C:\ProgramData\MAGIX
2016-01-07 18:25 - 2016-01-21 17:45 - 00000000 ____D C:\Program Files\Opera
2016-01-07 18:25 - 2016-01-07 18:25 - 00001093 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Opera.lnk
2016-01-07 18:25 - 2016-01-07 18:25 - 00000000 ____D C:\Users\kristian\AppData\Roaming\Opera Software
2016-01-07 18:25 - 2016-01-07 18:25 - 00000000 ____D C:\Users\kristian\AppData\Local\Opera Software
2016-01-07 18:21 - 2016-01-07 18:27 - 00000000 ____D C:\ProgramData\simplitec
2016-01-07 18:21 - 2015-05-06 16:54 - 00120200 _____ () C:\Windows\system32\DLLDEV32i.dll
2016-01-07 18:20 - 2016-01-15 13:14 - 00000000 ____D C:\KMPlayer
2016-01-07 18:15 - 2016-01-07 18:15 - 00720328 _____ (Opera Software) C:\Users\kristian\Downloads\Opera_NI_stable.exe
2016-01-05 22:12 - 2016-01-07 22:13 - 00000000 ____D C:\Users\kristian\AppData\Roaming\DMCache
2016-01-05 22:12 - 2016-01-05 22:12 - 00000000 ____D C:\ProgramData\IDM
2016-01-05 22:10 - 2016-01-05 22:11 - 06757552 _____ (Tonec Inc.) C:\Users\kristian\Downloads\idman625build10.exe
==================== One Month Modified files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2016-01-30 17:34 - 2015-12-24 10:29 - 00000000 ____D C:\Users\kristian\AppData\Local\CrashDumps
2016-01-30 17:26 - 2009-07-14 05:34 - 00014944 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2016-01-30 17:26 - 2009-07-14 05:34 - 00014944 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2016-01-30 17:19 - 2015-08-05 08:26 - 00000924 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2016-01-30 12:12 - 2015-11-27 18:05 - 00000000 ____D C:\Users\kristian\AppData\Roaming\Seznam.cz
2016-01-30 12:07 - 2015-11-20 08:39 - 00000000 ___RD C:\Users\kristian\Disk Google
2016-01-30 12:07 - 2015-08-05 08:34 - 00000000 ____D C:\ProgramData\NVIDIA
2016-01-30 12:07 - 2015-08-05 08:26 - 00000920 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2016-01-30 12:07 - 2009-07-14 05:53 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2016-01-30 10:25 - 2015-08-07 19:04 - 00000000 ____D C:\Program Files\Steam
2016-01-30 10:01 - 2015-11-29 19:34 - 00000000 ____D C:\Users\kristian\AppData\Roaming\uTorrent
2016-01-29 12:44 - 2009-07-14 03:37 - 00000000 ____D C:\Windows\inf
2016-01-29 08:24 - 2015-08-05 08:26 - 00002170 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2016-01-28 19:42 - 2015-08-05 08:23 - 00782470 _____ C:\Windows\system32\PerfStringBackup.INI
2016-01-28 17:47 - 2015-08-07 17:42 - 00000000 ____D C:\Program Files\CCleaner
2016-01-28 17:10 - 2015-08-05 08:22 - 00000000 ____D C:\Users\kristian
2016-01-28 17:09 - 2015-08-07 09:58 - 00000000 ___SD C:\Windows\system32\GWX
2016-01-28 17:09 - 2009-07-14 08:50 - 00000000 ___RD C:\Users\Public\Recorded TV
2016-01-28 17:09 - 2009-07-14 03:37 - 00000000 ____D C:\Windows\registration
2016-01-24 21:52 - 2015-08-07 18:18 - 00000000 ____D C:\Users\kristian\AppData\Roaming\Skype
2016-01-24 20:27 - 2015-12-30 17:39 - 00000000 ____D C:\Users\kristian\AppData\Roaming\.minecraft
2016-01-23 18:31 - 2015-08-09 19:38 - 00000000 ____D C:\ProgramData\Oracle
2016-01-23 18:29 - 2015-08-09 19:39 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java
2016-01-23 18:29 - 2015-08-09 19:38 - 00000000 ____D C:\Program Files\Java
2016-01-23 18:28 - 2015-11-08 10:45 - 00000000 ____D C:\Users\kristian\.oracle_jre_usage
2016-01-23 18:28 - 2015-08-09 19:39 - 00095840 _____ (Oracle Corporation) C:\Windows\system32\WindowsAccessBridge.dll
2016-01-22 20:12 - 2015-08-05 08:53 - 00000000 ___HD C:\Program Files\Temp
2016-01-22 20:10 - 2015-08-05 08:51 - 00000000 ___HD C:\Program Files\InstallShield Installation Information
2016-01-22 19:50 - 2015-08-05 16:48 - 00000000 ____D C:\Users\kristian\AppData\Local\NVIDIA
2016-01-18 17:19 - 2015-08-24 11:17 - 00000000 ____D C:\ProgramData\Package Cache
2016-01-14 17:38 - 2015-08-05 08:22 - 00000000 ____D C:\ProgramData\AVAST Software
2016-01-13 08:47 - 2015-08-05 08:05 - 00002441 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Reader XI.lnk
2016-01-12 05:41 - 2015-12-02 10:17 - 00091568 _____ C:\Windows\system32\NvRtmpStreamer32.dll
2016-01-12 05:41 - 2015-08-08 08:57 - 01542600 _____ (NVIDIA Corporation) C:\Windows\system32\nvspcap.dll
2016-01-12 05:41 - 2015-08-08 08:57 - 01316184 _____ (NVIDIA Corporation) C:\Windows\system32\nvspbridge.dll
2016-01-10 13:12 - 2015-08-05 08:22 - 00109280 _____ C:\Users\kristian\AppData\Local\GDIPFONTCACHEV1.DAT
2016-01-08 07:59 - 2009-07-14 05:33 - 03805776 _____ C:\Windows\system32\FNTCACHE.DAT
2016-01-04 12:25 - 2015-10-30 22:19 - 00000000 ____D C:\Users\kristian\Desktop\Christian
==================== Files in the root of some directories =======
2015-08-17 19:14 - 2015-08-24 15:26 - 0000216 _____ () C:\Program Files\VideoConfig.txt
Some files in TEMP:
====================
C:\Users\kristian\AppData\Local\Temp\avgnt.exe
==================== Bamital & volsnap =================
(There is no automatic fix for files that do not pass verification.)
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\system32\winlogon.exe => File is digitally signed
C:\Windows\system32\wininit.exe => File is digitally signed
C:\Windows\system32\svchost.exe => File is digitally signed
C:\Windows\system32\services.exe => File is digitally signed
C:\Windows\system32\User32.dll => File is digitally signed
C:\Windows\system32\userinit.exe => File is digitally signed
C:\Windows\system32\rpcss.dll => File is digitally signed
C:\Windows\system32\dnsapi.dll => File is digitally signed
C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed
LastRegBack: 2016-01-29 09:27
==================== End of FRST.txt ============================