Advertising Support - vyskakujúce reklamy v prehliadači
Napsal: 09 bře 2016 22:08
Dobrý deň, mám problém s reklamami, ktoré mi vyskakujú v prehliadači na rôznych stránkach - viď screenshot.
Posielam scan FRST:
Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version:05-03-2016 01
Ran by Jakubko (administrator) on JAKUB (09-03-2016 21:54:23)
Running from C:\Users\Jakubko\Downloads
Loaded Profiles: Jakubko & (Available Profiles: Jakubko & Free)
Platform: Windows 8 (X64) Language: Slovenčina (Slovensko)
Internet Explorer Version 10 (Default browser: Chrome)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/33 ... scan-tool/
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(ESET) C:\Program Files\ESET\ESET Smart Security\x86\ekrn.exe
(LogMeIn, Inc.) C:\Program Files (x86)\LogMeIn Hamachi\LMIGuardianSvc.exe
(TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe
(LogMeIn Inc.) C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2.exe
(Microsoft Corporation) C:\Windows\System32\alg.exe
(ASUSTek Computer Inc.) C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\AsLdrSrv.exe
(ASUS) C:\Program Files (x86)\ASUS\ATK Package\ATKGFNEX\GFNEXSrv.exe
(IVT Corporation) C:\Program Files (x86)\Ralink Corporation\Ralink Bluetooth Stack\BlueSoleilCS.exe
(IVT Corporation) C:\Program Files (x86)\Ralink Corporation\Ralink Bluetooth Stack\BsHelpCS.exe
(Intel(R) Corporation) C:\Program Files\Intel\iCLS Client\HeciServer.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\Jhi_service.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
(Adobe Systems, Incorporated) C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGSService.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(ESET) C:\Program Files\ESET\ESET Smart Security\egui.exe
(ASUSTek Computer Inc.) C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControl.exe
(ASUSTeK Computer Inc.) C:\Windows\System32\FBAgent.exe
(ASUSTek Computer Inc.) C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\KBFiltr.exe
(ASUSTek Computer Inc.) C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe
(ASUSTek Computer Inc.) C:\Program Files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe
(Logitech Inc.) C:\Program Files\Logitech\Gaming Software\LWEMon.exe
(ESET) C:\Program Files\ESET\ESET Smart Security\egui.exe
(Filipe Lourenço) C:\Program Files (x86)\BatteryCare\BatteryCare.exe
(Flux Software LLC) C:\Users\Jakubko\AppData\Local\FluxSoftware\Flux\flux.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(ASUS) C:\Program Files (x86)\ASUS\Splendid\ACMON.exe
(ASUSTeK) C:\Windows\SysWOW64\ACEngSvr.exe
(Intel Corporation) C:\Windows\System32\igfxpers.exe
(IVT Corporation) C:\Program Files (x86)\Ralink Corporation\Ralink Bluetooth Stack\BtTray.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
(ASUS) C:\Program Files\ASUS\P4G\BatteryLife.exe
(ASUSTek Computer Inc.) C:\Program Files (x86)\ASUS\USBChargerPlus\USBChargerPlus.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(BitTorrent Inc.) C:\Users\Jakubko\AppData\Roaming\uTorrent\uTorrent.exe
(BitTorrent Inc.) C:\Users\Jakubko\AppData\Roaming\uTorrent\updates\3.4.5_41865\utorrentie.exe
(BitTorrent Inc.) C:\Users\Jakubko\AppData\Roaming\uTorrent\updates\3.4.5_41865\utorrentie.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
() C:\Users\Jakubko\AppData\Roaming\ACEStream\engine\ace_engine.exe
() C:\Users\Jakubko\AppData\Roaming\ACEStream\updater\ace_update.exe
(Malwarebytes) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe
(Malwarebytes) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe
(Malwarebytes) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbam.exe
(Microsoft Corporation) C:\Windows\SysWOW64\notepad.exe
(Microsoft Corporation) C:\Windows\System32\rundll32.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
==================== Registry (Whitelisted) ===========================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [AdobeAAMUpdater-1.0] => C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [508240 2015-08-05] (Adobe Systems Incorporated)
HKLM\...\Run: [Start WingMan Profiler] => C:\Program Files\Logitech\Gaming Software\LWEMon.exe [190536 2010-06-14] (Logitech Inc.)
HKLM\...\Run: [egui] => C:\Program Files\ESET\ESET Smart Security\egui.exe [5595848 2015-07-08] (ESET)
HKLM\...\Run: [] => [X]
HKLM\...\Run: [AdAwareTray] => C:\Program Files\Lavasoft\Ad-Aware Antivirus\Ad-Aware Antivirus\11.10.767.8917\AdAwareTray.exe [9581280 2016-01-28] ()
HKLM-x32\...\Run: [SwitchBoard] => C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [517096 2010-02-19] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [AdobeCS5ServiceManager] => C:\Program Files (x86)\Common Files\Adobe\CS5ServiceManager\CS5ServiceManager.exe [402432 2010-07-22] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [958576 2013-04-04] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [AdobeCS6ServiceManager] => C:\Program Files (x86)\Common Files\Adobe\CS6ServiceManager\CS6ServiceManager.exe [1075296 2013-04-25] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [LogMeIn Hamachi Ui] => C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe [5565448 2015-11-12] (LogMeIn Inc.)
HKLM-x32\...\Run: [BlueStacks Agent] => C:\Program Files (x86)\BlueStacks\HD-Agent.exe
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [594992 2016-01-29] (Oracle Corporation)
Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation)
HKU\S-1-5-21-303898890-2447975317-2344255173-1001\...\Run: [RocketDock] => "C:\Program Files\RocketDock\RocketDock.exe"
HKU\S-1-5-21-303898890-2447975317-2344255173-1001\...\Run: [DU Meter] => "C:\Program Files (x86)\DU Meter\DUMeter.exe" /autostart
HKU\S-1-5-21-303898890-2447975317-2344255173-1001\...\Run: [AdobeBridge] => [X]
HKU\S-1-5-21-303898890-2447975317-2344255173-1001\...\Run: [BatteryCare] => C:\Program Files (x86)\BatteryCare\BatteryCare.exe [796160 2015-10-25] (Filipe Lourenço)
HKU\S-1-5-21-303898890-2447975317-2344255173-1001\...\Run: [CCleaner Monitoring] => C:\Program Files\CCleaner\CCleaner64.exe [8461224 2015-09-16] (Piriform Ltd)
HKU\S-1-5-21-303898890-2447975317-2344255173-1001\...\RunOnce: [Uninstall C:\Users\Jakubko\AppData\Local\Microsoft\SkyDrive\16.4.6013.0910\amd64] => C:\Windows\system32\cmd.exe /q /c rmdir /s /q "C:\Users\Jakubko\AppData\Local\Microsoft\SkyDrive\16.4.6013.0910\amd64"
HKU\S-1-5-21-303898890-2447975317-2344255173-1001\...\RunOnce: [Uninstall C:\Users\Jakubko\AppData\Local\Microsoft\SkyDrive\17.0.2015.0811\amd64] => C:\Windows\system32\cmd.exe /q /c rmdir /s /q "C:\Users\Jakubko\AppData\Local\Microsoft\SkyDrive\17.0.2015.0811\amd64"
HKU\S-1-5-21-303898890-2447975317-2344255173-1001\...\MountPoints2: {303d40f4-261a-11e5-bec4-b8763f0ffd04} - "G:\LG_PC_Programs.exe"
HKU\S-1-5-21-303898890-2447975317-2344255173-1001\...\MountPoints2: {412c5d44-2201-11e3-be77-b8763f0ffd04} - "G:\HTC_Sync_Manager_PC.exe"
HKU\S-1-5-21-303898890-2447975317-2344255173-1001\...\MountPoints2: {692bc9db-5d11-11e3-be7a-b8763f0ffd04} - "G:\HTC_Sync_Manager_PC.exe"
HKU\S-1-5-21-303898890-2447975317-2344255173-1001\...\MountPoints2: {6e1c7d43-2f64-11e3-be77-b8763f0ffd04} - "F:\autorun.exe"
HKU\S-1-5-21-303898890-2447975317-2344255173-1001\...\MountPoints2: {846c8ad3-31ec-11e3-be78-b8763f0ffd04} - "E:\Autorun.exe"
HKU\S-1-5-21-303898890-2447975317-2344255173-1001\Control Panel\Desktop\\SCRNSAVE.EXE ->
HKU\S-1-5-21-303898890-2447975317-2344255173-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\Run: [RocketDock] => "C:\Program Files\RocketDock\RocketDock.exe"
HKU\S-1-5-21-303898890-2447975317-2344255173-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\Run: [DU Meter] => "C:\Program Files (x86)\DU Meter\DUMeter.exe" /autostart
HKU\S-1-5-21-303898890-2447975317-2344255173-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\Run: [AdobeBridge] => [X]
HKU\S-1-5-21-303898890-2447975317-2344255173-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\Run: [BatteryCare] => C:\Program Files (x86)\BatteryCare\BatteryCare.exe [796160 2015-10-25] (Filipe Lourenço)
HKU\S-1-5-21-303898890-2447975317-2344255173-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\Run: [CCleaner Monitoring] => C:\Program Files\CCleaner\CCleaner64.exe [8461224 2015-09-16] (Piriform Ltd)
HKU\S-1-5-21-303898890-2447975317-2344255173-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\RunOnce: [Uninstall C:\Users\Jakubko\AppData\Local\Microsoft\SkyDrive\16.4.6013.0910\amd64] => C:\Windows\system32\cmd.exe /q /c rmdir /s /q "C:\Users\Jakubko\AppData\Local\Microsoft\SkyDrive\16.4.6013.0910\amd64"
HKU\S-1-5-21-303898890-2447975317-2344255173-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\RunOnce: [Uninstall C:\Users\Jakubko\AppData\Local\Microsoft\SkyDrive\17.0.2015.0811\amd64] => C:\Windows\system32\cmd.exe /q /c rmdir /s /q "C:\Users\Jakubko\AppData\Local\Microsoft\SkyDrive\17.0.2015.0811\amd64"
HKU\S-1-5-21-303898890-2447975317-2344255173-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\MountPoints2: {303d40f4-261a-11e5-bec4-b8763f0ffd04} - "G:\LG_PC_Programs.exe"
HKU\S-1-5-21-303898890-2447975317-2344255173-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\MountPoints2: {412c5d44-2201-11e3-be77-b8763f0ffd04} - "G:\HTC_Sync_Manager_PC.exe"
HKU\S-1-5-21-303898890-2447975317-2344255173-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\MountPoints2: {692bc9db-5d11-11e3-be7a-b8763f0ffd04} - "G:\HTC_Sync_Manager_PC.exe"
HKU\S-1-5-21-303898890-2447975317-2344255173-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\MountPoints2: {6e1c7d43-2f64-11e3-be77-b8763f0ffd04} - "F:\autorun.exe"
HKU\S-1-5-21-303898890-2447975317-2344255173-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\MountPoints2: {846c8ad3-31ec-11e3-be78-b8763f0ffd04} - "E:\Autorun.exe"
HKU\S-1-5-21-303898890-2447975317-2344255173-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\Control Panel\Desktop\\SCRNSAVE.EXE ->
ShellIconOverlayIdentifiers: ["DropboxExt1"] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Jakubko\AppData\Roaming\Dropbox\bin\DropboxExt64.25.dll [2015-02-11] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: ["DropboxExt2"] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Jakubko\AppData\Roaming\Dropbox\bin\DropboxExt64.25.dll [2015-02-11] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: ["DropboxExt3"] -> {FB314EDD-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Jakubko\AppData\Roaming\Dropbox\bin\DropboxExt64.25.dll [2015-02-11] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: ["DropboxExt4"] -> {FB314EDE-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Jakubko\AppData\Roaming\Dropbox\bin\DropboxExt64.25.dll [2015-02-11] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: ["DropboxExt5"] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Jakubko\AppData\Roaming\Dropbox\bin\DropboxExt64.25.dll [2015-02-11] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: ["DropboxExt6"] -> {FB314EDF-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Jakubko\AppData\Roaming\Dropbox\bin\DropboxExt64.25.dll [2015-02-11] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: ["DropboxExt7"] -> {FB314EDC-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Jakubko\AppData\Roaming\Dropbox\bin\DropboxExt64.25.dll [2015-02-11] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: ["DropboxExt8"] -> {FB314EE0-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Jakubko\AppData\Roaming\Dropbox\bin\DropboxExt64.25.dll [2015-02-11] (Dropbox, Inc.)
Startup: C:\Users\Jakubko\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk [2015-02-25]
ShortcutTarget: Dropbox.lnk -> C:\Users\Jakubko\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
Hosts: There are more than one entry in Hosts. See Hosts section of Addition.txt
Tcpip\Parameters: [DhcpNameServer] 158.195.6.2 158.195.6.3 158.195.4.3
Tcpip\..\Interfaces\{B19DAFF3-11D7-491A-B8B8-3C62919F0E54}: [DhcpNameServer] 158.195.6.2 158.195.6.3 158.195.4.3
Internet Explorer:
==================
HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer: Restriction <======= ATTENTION
HKU\S-1-5-21-303898890-2447975317-2344255173-1001\Software\Microsoft\Internet Explorer\Main,Start Page = about:Tabs
HKU\S-1-5-21-303898890-2447975317-2344255173-1001\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://asus13.msn.com
HKU\S-1-5-21-303898890-2447975317-2344255173-1001\Software\Microsoft\Internet Explorer\Main,Search Bar = hxxp://www.google.com/ie
HKU\S-1-5-21-303898890-2447975317-2344255173-1001\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://www.google.com/ie
HKU\S-1-5-21-303898890-2447975317-2344255173-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\Software\Microsoft\Internet Explorer\Main,Start Page = about:Tabs
HKU\S-1-5-21-303898890-2447975317-2344255173-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://asus13.msn.com
HKU\S-1-5-21-303898890-2447975317-2344255173-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\Software\Microsoft\Internet Explorer\Main,Search Bar = hxxp://www.google.com/ie
HKU\S-1-5-21-303898890-2447975317-2344255173-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://www.google.com/ie
HKU\S-1-5-21-303898890-2447975317-2344255173-1005-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://asus13.msn.com
HKU\S-1-5-21-303898890-2447975317-2344255173-1005-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://asus13.msn.com
SearchScopes: HKU\S-1-5-21-303898890-2447975317-2344255173-1001 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-21-303898890-2447975317-2344255173-1001 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-21-303898890-2447975317-2344255173-1001 -> {6A1806CD-94D4-4689-BA73-E35EA1EA9990} URL = hxxp://www.google.com/search?q={sear
SearchScopes: HKU\S-1-5-21-303898890-2447975317-2344255173-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-21-303898890-2447975317-2344255173-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-21-303898890-2447975317-2344255173-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0 -> {6A1806CD-94D4-4689-BA73-E35EA1EA9990} URL = hxxp://www.google.com/search?q={sear
BHO: Lync Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files\Microsoft Office\Office15\OCHelper.dll [2012-10-01] (Microsoft Corporation)
BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office\Office15\URLREDIR.DLL [2012-10-01] (Microsoft Corporation)
BHO: Microsoft SkyDrive Pro Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files\Microsoft Office\Office15\GROOVEEX.DLL [2012-10-01] (Microsoft Corporation)
BHO-x32: Lync Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files (x86)\Microsoft Office\Office15\OCHelper.dll [2012-10-01] (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_73\bin\ssv.dll [2016-02-14] (Oracle Corporation)
BHO-x32: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files (x86)\Microsoft Office\Office15\URLREDIR.DLL [2012-10-01] (Microsoft Corporation)
BHO-x32: Microsoft SkyDrive Pro Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files (x86)\Microsoft Office\Office15\GROOVEEX.DLL [2012-10-01] (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_73\bin\jp2ssv.dll [2016-02-14] (Oracle Corporation)
Handler: osf - {D924BDC6-C83A-4BD5-90D0-095128A113D1} - C:\Program Files\Microsoft Office\Office15\MSOSB.DLL [2012-10-01] (Microsoft Corporation)
FireFox:
========
FF ProfilePath: C:\Users\Jakubko\AppData\Roaming\Mozilla\Firefox\Profiles\vidg21l8.default
FF Plugin: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~1\MICROS~1\Office15\NPSPWRAP.DLL [2012-10-01] (Microsoft Corporation)
FF Plugin: adobe.com/AdobeAAMDetect -> C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\CCM\Utilities\npAdobeAAMDetect64.dll [2015-08-06] (Adobe Systems)
FF Plugin: adobe.com/AdobeExManDetect -> C:\Program Files (x86)\Adobe\Adobe Extension Manager CS6\Win64Plugin\npAdobeExManDetectX64.dll [2013-12-02] (Adobe Systems)
FF Plugin-x32: @google.com/npPicasa3,version=3.0.0 -> C:\Program Files (x86)\Google\Picasa3\npPicasa3.dll [2015-02-13] (Google, Inc.)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=2.1.42 -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll [2012-06-06] (Intel Corporation)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll [2012-06-06] (Intel Corporation)
FF Plugin-x32: @java.com/DTPlugin,version=11.73.2 -> C:\Program Files (x86)\Java\jre1.8.0_73\bin\dtplugin\npDeployJava1.dll [2016-02-14] (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=11.73.2 -> C:\Program Files (x86)\Java\jre1.8.0_73\bin\plugin2\npjp2.dll [2016-02-14] (Oracle Corporation)
FF Plugin-x32: @microsoft.com/Lync,version=15.0 -> C:\Program Files (x86)\Mozilla Firefox\plugins\npmeetingjoinpluginoc.dll [2012-10-01] (Microsoft Corporation)
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files (x86)\Microsoft Silverlight\5.1.40416.0\npctrl.dll [2015-04-15] ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~2\MICROS~1\Office15\NPSPWRAP.DLL [2012-10-01] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=16.4.3505.0912 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2012-09-12] (Microsoft Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.29.5\npGoogleUpdate3.dll [2016-02-02] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.29.5\npGoogleUpdate3.dll [2016-02-02] (Google Inc.)
FF Plugin-x32: @veetle.com/veetleCorePlugin,version=0.9.19 -> C:\Program Files (x86)\Veetle\plugins\npVeetle.dll [2012-01-14] (Veetle Inc)
FF Plugin-x32: @veetle.com/veetlePlayerPlugin,version=0.9.18 -> C:\Program Files (x86)\Veetle\Player\npvlc.dll [2012-01-14] (Veetle Inc)
FF Plugin-x32: @videolan.org/vlc,version=2.0.5 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2012-12-13] (VideoLAN)
FF Plugin-x32: @videolan.org/vlc,version=2.1.0 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2012-12-13] (VideoLAN)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll [2013-09-03] (Adobe Systems Inc.)
FF Plugin-x32: adobe.com/AdobeAAMDetect -> C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\CCM\Utilities\npAdobeAAMDetect32.dll [2015-08-06] (Adobe Systems)
FF Plugin-x32: adobe.com/AdobeExManDetect -> C:\Program Files (x86)\Adobe\Adobe Extension Manager CS6\npAdobeExManDetectX86.dll [2013-12-02] (Adobe Systems)
FF Plugin HKU\S-1-5-21-303898890-2447975317-2344255173-1001: @acestream.net/acestreamplugin,version=2.2.2-next -> C:\Users\Jakubko\AppData\Roaming\ACEStream\player\npace_plugin.dll [2014-07-09] (Innovative Digital Technologies)
FF Plugin HKU\S-1-5-21-303898890-2447975317-2344255173-1001: @Skype Limited.com/Facebook Video Calling Plugin -> C:\Users\Jakubko\AppData\Local\Facebook\Video\Skype\npFacebookVideoCalling.dll [2014-07-24] (Skype Limited)
FF Plugin HKU\S-1-5-21-303898890-2447975317-2344255173-1001: @unity3d.com/UnityPlayer,version=1.0 -> C:\Users\Jakubko\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll [2009-11-30] (Unity Technologies ApS)
FF Plugin HKU\S-1-5-21-303898890-2447975317-2344255173-1001: anvisoft.com/AdblockPlugin -> C:\ProgramData\Anvisoft\Anvi Smart Defender 2\extensions\npAdblockPlugin.dll [No File]
FF Plugin HKU\S-1-5-21-303898890-2447975317-2344255173-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0: @acestream.net/acestreamplugin,version=2.2.2-next -> C:\Users\Jakubko\AppData\Roaming\ACEStream\player\npace_plugin.dll [2014-07-09] (Innovative Digital Technologies)
FF Plugin HKU\S-1-5-21-303898890-2447975317-2344255173-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0: @Skype Limited.com/Facebook Video Calling Plugin -> C:\Users\Jakubko\AppData\Local\Facebook\Video\Skype\npFacebookVideoCalling.dll [2014-07-24] (Skype Limited)
FF Plugin HKU\S-1-5-21-303898890-2447975317-2344255173-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0: @unity3d.com/UnityPlayer,version=1.0 -> C:\Users\Jakubko\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll [2009-11-30] (Unity Technologies ApS)
FF Plugin HKU\S-1-5-21-303898890-2447975317-2344255173-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0: anvisoft.com/AdblockPlugin -> C:\ProgramData\Anvisoft\Anvi Smart Defender 2\extensions\npAdblockPlugin.dll [No File]
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npMeetingJoinPluginOC.dll [2012-10-01] (Microsoft Corporation)
FF Extension: Gmail panel - C:\Users\Jakubko\AppData\Roaming\Mozilla\Firefox\Profiles\vidg21l8.default\extensions\gmail_panel@alejandrobrizuela.com.ar.xpi [2016-01-14]
FF Extension: Fasterfox - C:\Users\Jakubko\AppData\Roaming\Mozilla\Firefox\Profiles\vidg21l8.default\extensions\{c36177c0-224a-11da-8cd6-0800200c9a91}.xpi [2016-01-14]
FF Extension: Adblock Plus - C:\Users\Jakubko\AppData\Roaming\Mozilla\Firefox\Profiles\vidg21l8.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2016-01-14]
FF HKLM\...\Thunderbird\Extensions: [eplgTb@eset.com] - C:\Program Files\ESET\ESET Smart Security\Mozilla Thunderbird => not found
FF HKLM-x32\...\Thunderbird\Extensions: [msktbird@mcafee.com] - C:\Program Files\McAfee\MSK => not found
FF HKLM-x32\...\Thunderbird\Extensions: [eplgTb@eset.com] - C:\Program Files\ESET\ESET Smart Security\Mozilla Thunderbird => not found
FF HKU\S-1-5-21-303898890-2447975317-2344255173-1001\...\Firefox\Extensions: [magicplayer@torrentstream.org] - C:\Users\Jakubko\AppData\Roaming\ACEStream\extensions\firefox\magicplayer@torrentstream.org
FF Extension: TS Magic Player - C:\Users\Jakubko\AppData\Roaming\ACEStream\extensions\firefox\magicplayer@torrentstream.org [2014-09-13] [not signed]
FF HKU\S-1-5-21-303898890-2447975317-2344255173-1001\...\SeaMonkey\Extensions: [mozilla_cc2@internetdownloadmanager.com] - C:\Program Files (x86)\Internet Download Manager\idmmzcc2.xpi => not found
FF HKU\S-1-5-21-303898890-2447975317-2344255173-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\Firefox\Extensions: [magicplayer@torrentstream.org] - C:\Users\Jakubko\AppData\Roaming\ACEStream\extensions\firefox\magicplayer@torrentstream.org
FF HKU\S-1-5-21-303898890-2447975317-2344255173-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\SeaMonkey\Extensions: [mozilla_cc2@internetdownloadmanager.com] - C:\Program Files (x86)\Internet Download Manager\idmmzcc2.xpi => not found
Chrome:
=======
CHR Plugin: (Shockwave Flash) - C:\Program Files (x86)\Google\Chrome\Application\47.0.2526.106\PepperFlash\pepflashplayer.dll => No File
CHR Plugin: (Native Client) - C:\Program Files (x86)\Google\Chrome\Application\48.0.2564.116\ppGoogleNaClPluginChrome.dll => No File
CHR Plugin: (Chrome PDF Viewer) - C:\Program Files (x86)\Google\Chrome\Application\48.0.2564.116\pdf.dll => No File
CHR Plugin: (Adobe Acrobat) - C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Browser\nppdf32.dll (Adobe Systems Inc.)
CHR Plugin: (Google Update) - C:\Program Files (x86)\Google\Update\1.3.21.153\npGoogleUpdate3.dll => No File
CHR Plugin: (Intel® Identity Protection Technology) - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll (Intel Corporation)
CHR Plugin: (Intel® Identity Protection Technology) - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll (Intel Corporation)
CHR Plugin: (Photo Gallery) - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
CHR Plugin: (McAfee SecurityCenter) - c:\progra~2\mcafee\msc\npmcsn~1.dll => No File
CHR Profile: C:\Users\Jakubko\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (Dokumenty Google) - C:\Users\Jakubko\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2016-01-14]
CHR Extension: (YouTube) - C:\Users\Jakubko\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2016-01-14]
CHR Extension: (Google Search) - C:\Users\Jakubko\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2016-01-14]
CHR Extension: (Gmail™ Notifier) - C:\Users\Jakubko\AppData\Local\Google\Chrome\User Data\Default\Extensions\dcjichoefijpinlfnjghokpkojhlhkgl [2016-02-05]
CHR Extension: (Dokumenty Google v režime offline) - C:\Users\Jakubko\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2016-01-14]
CHR Extension: (AdBlock) - C:\Users\Jakubko\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom [2016-02-21]
CHR Extension: (AS Magic Player) - C:\Users\Jakubko\AppData\Local\Google\Chrome\User Data\Default\Extensions\mfhnkgpdlogbknkhlgdjlejeljbhflim [2016-01-18]
CHR Extension: (F.B Purity-Clean Up Facebook) - C:\Users\Jakubko\AppData\Local\Google\Chrome\User Data\Default\Extensions\ncdlagniojmheiklojdcpdaeepochckl [2016-03-04]
CHR Extension: (Gmail) - C:\Users\Jakubko\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2016-01-14]
CHR HKLM\...\Chrome\Extension: [ngpampappnmepgilojfohadhhmbhlaek] - C:\Program Files (x86)\Internet Download Manager\IDMGCExt.crx <not found>
CHR HKU\S-1-5-21-303898890-2447975317-2344255173-1001\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [kpckgflgdapkpabemgkielbefdildaio] - C:\Users\Jakubko\AppData\Roaming\ACEStream\extensions\chrome_new\magicplayer.crx [2014-01-28]
CHR HKU\S-1-5-21-303898890-2447975317-2344255173-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [kpckgflgdapkpabemgkielbefdildaio] - C:\Users\Jakubko\AppData\Roaming\ACEStream\extensions\chrome_new\magicplayer.crx [2014-01-28]
CHR HKLM-x32\...\Chrome\Extension: [lhmiofmipcpmhgihiecmpiekcacigpgb] - C:\ProgramData\Anvisoft\Anvi Smart Defender 2\extensions\chrome.crx <not found>
StartMenuInternet: chrome.exe - C:\Users\Jakubko\AppData\Local\Google\Chrome\Application\chrome.exe
==================== Services (Whitelisted) ========================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R2 AGSService; C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGSService.exe [2020056 2016-02-09] (Adobe Systems, Incorporated)
R3 BlueSoleilCS; C:\Program Files (x86)\Ralink Corporation\Ralink Bluetooth Stack\BlueSoleilCS.exe [1578496 2012-08-14] (IVT Corporation) [File not signed]
R3 BsHelpCS; C:\Program Files (x86)\Ralink Corporation\Ralink Bluetooth Stack\BsHelpCS.exe [138752 2012-08-14] (IVT Corporation) [File not signed]
R2 ekrn; C:\Program Files\ESET\ESET Smart Security\x86\ekrn.exe [1353720 2015-07-08] (ESET)
S3 IDriverT; C:\Program Files (x86)\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe [69632 2005-04-04] (Macrovision Corporation) [File not signed]
R3 Intel(R) ME Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe [129856 2012-06-27] (Intel Corporation)
R3 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [166720 2012-06-25] (Intel Corporation)
S2 LavasoftAdAwareService11; C:\Program Files\Lavasoft\Ad-Aware Antivirus\Ad-Aware Antivirus\11.10.767.8917\AdAwareService.exe [712432 2016-01-28] ()
R2 LMIGuardianSvc; C:\Program Files (x86)\LogMeIn Hamachi\LMIGuardianSvc.exe [417552 2015-11-12] (LogMeIn, Inc.)
R2 MBAMScheduler; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe [1513784 2015-10-05] (Malwarebytes)
R2 MBAMService; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe [1135416 2015-10-05] (Malwarebytes)
S3 Origin Client Service; C:\Program Files (x86)\Origin\OriginClientService.exe [2057736 2015-09-08] (Electronic Arts)
S3 SwitchBoard; C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [517096 2010-02-19] (Adobe Systems Incorporated) [File not signed]
R2 TeamViewer; C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe [6889232 2015-12-14] (TeamViewer GmbH)
S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [16048 2013-07-02] (Microsoft Corporation)
S2 mcbootdelaystartsvc; "C:\Program Files\Common Files\mcafee\McSvcHost\McSvHost.exe" /McCoreSvc [X]
===================== Drivers (Whitelisted) ==========================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R3 Apowersoft_AudioDevice; C:\Windows\system32\drivers\Apowersoft_AudioDevice.sys [31920 2014-04-09] (Wondershare)
S3 ATP; C:\Windows\System32\drivers\AsusTP.sys [65784 2013-01-16] (ASUS Corporation)
S3 avc3; C:\Windows\System32\DRIVERS\avc3.sys [1600512 2016-01-05] (BitDefender)
R3 avchv; C:\Windows\system32\DRIVERS\avchv.sys [282000 2016-01-05] (BitDefender)
S3 avckf; C:\Windows\System32\DRIVERS\avckf.sys [775424 2016-01-05] (BitDefender)
R1 BdfNdisf; C:\Program Files\Lavasoft\Ad-Aware Antivirus\Firewall Engine\1.6.0.0\Drivers\bdfndisf6.sys [97816 2015-01-06] (BitDefender LLC)
R1 bdfwfpf; C:\Program Files\Lavasoft\Ad-Aware Antivirus\Firewall Engine\1.6.0.0\Drivers\bdfwfpf.sys [107080 2015-01-06] (BitDefender LLC)
U5 BlueletAudio; C:\Windows\System32\Drivers\BlueletAudio.sys [34912 2012-06-15] (Ralink Corporation.)
R3 BtAudioBusSrv; C:\Windows\System32\Drivers\BtAudioBus.sys [23136 2012-06-15] (IVT Corporation)
U4 BthA2DP; C:\Windows\system32\drivers\BthA2DP.sys [117632 2013-06-01] (Microsoft Corporation)
R3 BthL2caScoIfSrv; C:\Windows\System32\Drivers\BtL2caScoIf.sys [56904 2012-07-19] (Ralink Corporation)
R3 btUrbFilterDrv; C:\Windows\System32\Drivers\IvtUrbBtFlt.sys [48736 2012-08-14] (Ralink Corporation)
R1 dtsoftbus01; C:\Windows\System32\drivers\dtsoftbus01.sys [283064 2013-10-10] (Disc Soft Ltd)
R1 eamonm; C:\Windows\System32\DRIVERS\eamonm.sys [255240 2015-07-14] (ESET)
S0 ebdrv; C:\Windows\System32\drivers\evbda.sys [3265256 2012-11-23] (Broadcom Corporation)
R0 edevmon; C:\Windows\System32\DRIVERS\edevmon.sys [251632 2015-07-14] (ESET)
R1 ehdrv; C:\Windows\system32\DRIVERS\ehdrv.sys [178520 2015-07-14] (ESET)
R2 epfw; C:\Windows\system32\DRIVERS\epfw.sys [231520 2015-07-14] (ESET)
R1 EpfwLWF; C:\Windows\system32\DRIVERS\EpfwLWF.sys [53360 2015-07-14] (ESET)
R0 epfwwfp; C:\Windows\System32\DRIVERS\epfwwfp.sys [72400 2015-07-14] (ESET)
S3 gzflt; C:\Program Files\Lavasoft\Ad-Aware Antivirus\Antimalware Engine\3.0.99.0\gzflt.sys [155912 2015-12-09] (BitDefender LLC)
R3 Hamachi; C:\Windows\system32\DRIVERS\Hamdrv.sys [45680 2015-11-12] (LogMeIn Inc.)
R3 kbfiltr; C:\Windows\System32\drivers\kbfiltr.sys [14992 2012-08-02] ( )
R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25816 2015-10-05] (Malwarebytes)
R3 MBAMSwissArmy; C:\Windows\system32\drivers\MBAMSwissArmy.sys [192216 2016-03-09] (Malwarebytes)
R3 MBAMWebAccessControl; C:\Windows\system32\drivers\mwac.sys [64216 2015-10-05] (Malwarebytes Corporation)
R3 rtbth; C:\Windows\System32\drivers\rtbth.sys [695392 2012-08-14] (Ralink Technology, Corp.)
R0 sptd; C:\Windows\System32\Drivers\sptd.sys [564824 2013-10-10] (Duplex Secure Ltd.)
S3 Trufos; C:\Windows\System32\DRIVERS\Trufos.sys [452040 2015-12-09] (BitDefender S.R.L.)
U5 UnlockerDriver5; C:\Program Files\Unlocker\UnlockerDriver5.sys [12352 2010-07-01] ()
S3 WdBoot; C:\Windows\system32\drivers\WdBoot.sys [36288 2013-07-02] (Microsoft Corporation)
S3 WdFilter; C:\Windows\system32\drivers\WdFilter.sys [247216 2013-07-01] (Microsoft Corporation)
S3 WinRing0_1_2_0; C:\Program Files (x86)\BatteryCare\WinRing0x64.sys [14544 2014-03-22] (OpenLibSys.org)
U3 amy5qqob; C:\Windows\System32\Drivers\amy5qqob.sys [0 ] (Intel Corporation) <==== ATTENTION (zero byte File/Folder)
U5 BlueletAudio; C:\Windows\SysWOW64\Drivers\BlueletAudio.sys [34912 2012-06-15] (Ralink Corporation.)
S3 DUMeterDrv; \??\C:\Program Files (x86)\DU Meter\DUMETR64.SYS [X]
U0 msahci; no ImagePath
S3 vmci; \SystemRoot\System32\drivers\vmci.sys [X]
S3 VMnetAdapter; \SystemRoot\system32\DRIVERS\vmnetadapter.sys [X]
==================== NetSvcs (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
==================== One Month Created files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2016-03-09 21:54 - 2016-03-09 21:56 - 00034731 _____ C:\Users\Jakubko\Downloads\FRST.txt
2016-03-09 21:53 - 2016-03-09 21:54 - 00000000 ____D C:\FRST
2016-03-09 21:53 - 2016-03-09 21:53 - 02374144 _____ (Farbar) C:\Users\Jakubko\Downloads\FRST64.exe
2016-03-09 21:43 - 2016-03-09 21:43 - 00388608 _____ (Trend Micro Inc.) C:\Users\Jakubko\Downloads\hijackthis.exe
2016-03-09 21:37 - 2016-03-09 21:37 - 00192216 _____ (Malwarebytes) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2016-03-09 21:35 - 2016-03-09 21:35 - 00001104 _____ C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2016-03-09 21:35 - 2016-03-09 21:35 - 00000000 ____D C:\ProgramData\Malwarebytes
2016-03-09 21:35 - 2016-03-09 21:35 - 00000000 ____D C:\Program Files (x86)\Malwarebytes Anti-Malware
2016-03-09 21:35 - 2015-10-05 09:50 - 00109272 _____ (Malwarebytes) C:\Windows\system32\Drivers\mbamchameleon.sys
2016-03-09 21:35 - 2015-10-05 09:50 - 00064216 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys
2016-03-09 21:35 - 2015-10-05 09:50 - 00025816 _____ (Malwarebytes) C:\Windows\system32\Drivers\mbam.sys
2016-03-09 21:34 - 2016-03-09 21:34 - 22908888 _____ (Malwarebytes ) C:\Users\Jakubko\Downloads\mbam-setup-2.2.0.1024.exe
2016-03-09 20:42 - 2016-03-09 21:30 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Anvisoft
2016-03-09 20:42 - 2016-03-09 20:42 - 00000000 ____D C:\ProgramData\boost_interprocess
2016-03-09 20:41 - 2015-09-17 02:52 - 00051608 _____ (Anvisoft) C:\Windows\system32\Drivers\asd2fsm.sys
2016-03-09 20:40 - 2016-03-09 20:40 - 00000000 ____D C:\ProgramData\Anvisoft
2016-03-09 20:40 - 2016-03-09 20:40 - 00000000 ____D C:\Program Files (x86)\Anvisoft
2016-03-09 20:39 - 2016-03-09 20:40 - 39269240 _____ (Anvisoft) C:\Users\Jakubko\Downloads\asdsetup.exe
2016-03-09 16:48 - 2016-03-09 16:48 - 00000000 ____D C:\Users\Jakubko\AppData\Roaming\Lavasoft
2016-03-09 16:36 - 2016-03-09 16:36 - 00000000 ____D C:\Users\Jakubko\AppData\Roaming\LavasoftStatistics
2016-03-09 16:35 - 2015-01-06 12:47 - 01061776 _____ (BitDefender S.R.L.) C:\Windows\system32\bdsmtpp.dll
2016-03-09 16:35 - 2015-01-06 12:47 - 00209984 _____ (BitDefender) C:\Windows\system32\BdFirewallSDK.dll
2016-03-09 16:35 - 2015-01-06 12:47 - 00195016 _____ (BitDefender) C:\Windows\system32\httproxy.dll
2016-03-09 16:35 - 2015-01-06 12:47 - 00156936 _____ C:\Windows\system32\bdfwcore.dll
2016-03-09 16:35 - 2015-01-06 12:47 - 00155912 _____ (BitDefender S.R.L.) C:\Windows\system32\bdpop3p.dll
2016-03-09 16:35 - 2015-01-06 12:47 - 00122928 _____ (BitDefender) C:\Windows\system32\OEMbdpredir.dll
2016-03-09 16:35 - 2015-01-06 12:47 - 00096160 _____ (BitDefender) C:\Windows\system32\bdpredir.dll
2016-03-09 16:33 - 2016-03-09 16:33 - 00000017 _____ C:\ProgramData\adaware-installer-reboot-required.tmp
2016-03-09 16:33 - 2016-03-09 16:33 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Lavasoft
2016-03-09 16:32 - 2016-03-09 16:32 - 00000000 ____H C:\Windows\system32\Drivers\Msft_Kernel_avchv_01009.Wdf
2016-03-09 16:32 - 2016-03-09 16:32 - 00000000 ____D C:\Windows\LastGood
2016-03-09 16:31 - 2016-03-09 16:31 - 00000000 ____D C:\Program Files\Lavasoft
2016-03-09 16:30 - 2016-03-09 16:30 - 00000000 ____D C:\Program Files\Common Files\Lavasoft
2016-03-09 16:29 - 2016-03-09 16:29 - 08493144 _____ C:\Users\Jakubko\Downloads\Adaware_Installer.exe
2016-03-09 16:29 - 2016-03-09 16:29 - 00000000 ____D C:\ProgramData\Lavasoft
2016-03-08 15:41 - 2016-03-08 15:42 - 44178450 _____ C:\Users\Jakubko\Downloads\MsZ 25.02.2016 #1 (online-video-cutter.com).mp4
2016-03-08 15:24 - 2016-03-09 17:40 - 00000000 ____D C:\ProgramData\Freemake
2016-03-08 15:24 - 2016-03-08 15:26 - 00000000 ____D C:\Users\Jakubko\Documents\Freemake
2016-03-08 15:24 - 2016-03-08 15:24 - 00001322 _____ C:\Users\Public\Desktop\Video Cutter.lnk
2016-03-08 15:22 - 2016-03-08 15:22 - 30968352 _____ (Ellora Assets Corporation ) C:\Users\Jakubko\Downloads\FreemakeVideoConverterFull.exe
2016-03-07 21:43 - 2016-03-07 21:43 - 00015102 _____ C:\Users\Jakubko\Downloads\int organisatons 15_16 evaluation.xlsx
2016-03-07 15:32 - 2016-03-07 15:33 - 41573347 _____ C:\Users\Jakubko\Downloads\Benefičný koncert venovaný spomienke Miňa Kočana.mp4
2016-03-07 15:24 - 2016-03-07 15:24 - 00000000 ____D C:\Users\Jakubko\AppData\LocalLow\uTorrent
2016-03-07 14:23 - 2016-03-07 14:23 - 00049244 _____ C:\Users\Jakubko\Desktop\Príkaz.PDF
2016-03-07 14:22 - 2016-03-07 14:22 - 00115495 _____ C:\Users\Jakubko\Desktop\Prihláška.pdf
2016-03-07 14:18 - 2016-03-07 14:18 - 00115495 _____ C:\Users\Jakubko\Downloads\gabor201457356745073.pdf
2016-03-07 14:18 - 2016-03-07 14:18 - 00049244 _____ C:\Users\Jakubko\Downloads\1457356747736.PDF
2016-03-07 11:39 - 2016-03-07 11:39 - 00005161 _____ C:\Users\Jakubko\Downloads\[kat.cr]the.walking.dead.s06e12.hdtv.x264.killers.ettv.torrent
2016-03-06 15:53 - 2016-03-06 15:53 - 00179538 _____ C:\Users\Jakubko\Downloads\Účasť poslancov msz na zasadnutiach - rok 2016 (1).pdf
2016-03-06 15:49 - 2016-03-06 15:49 - 00179538 _____ C:\Users\Jakubko\Downloads\Účasť poslancov msz na zasadnutiach - rok 2016.pdf
2016-03-06 15:48 - 2016-03-06 15:48 - 00288010 _____ C:\Users\Jakubko\Downloads\uznesenia msz 25. 02. 2016 - 156 - 185 - informácia.pdf
2016-03-06 13:25 - 2016-03-06 13:25 - 00000111 _____ C:\Users\Jakubko\Downloads\data-sdwsq.csv
2016-03-05 16:13 - 2016-03-05 16:13 - 00101552 _____ C:\Users\Jakubko\Downloads\MP-1501.pdf
2016-03-05 16:13 - 2016-03-05 16:13 - 00089832 _____ C:\Users\Jakubko\Downloads\KP-2015.pdf
2016-03-05 16:12 - 2016-03-05 16:12 - 00344608 _____ C:\Users\Jakubko\Downloads\RP-2015.xml
2016-03-05 16:12 - 2016-03-05 16:12 - 00025022 _____ C:\Users\Jakubko\Downloads\RP-2015.csv.zip
2016-03-05 16:11 - 2016-03-05 16:11 - 00104984 _____ C:\Users\Jakubko\Downloads\MP-1503.pdf
2016-03-05 16:10 - 2016-03-05 16:10 - 00000000 ____D C:\Users\Free.Jakub\AppData\Local\Adobe
2016-03-05 16:09 - 2016-03-05 16:11 - 00000000 ____D C:\Users\Free.Jakub\AppData\Roaming\Adobe
2016-03-05 16:09 - 2016-03-05 16:09 - 00002269 _____ C:\Users\Free.Jakub\Desktop\Google Chrome.lnk
2016-03-05 16:09 - 2016-03-05 16:09 - 00001432 _____ C:\Users\Free.Jakub\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
2016-03-05 16:09 - 2016-03-05 16:09 - 00000000 ____D C:\Users\Free.Jakub\AppData\Local\Google
2016-03-05 16:07 - 2016-03-05 16:09 - 00000000 ____D C:\Users\Free.Jakub\AppData\Local\Packages
2016-03-05 16:07 - 2016-03-05 16:07 - 00000000 ____D C:\Users\Free.Jakub\AppData\Local\VirtualStore
2016-03-05 16:06 - 2016-03-05 16:10 - 00000000 ____D C:\Users\Free.Jakub
2016-03-05 16:06 - 2016-03-05 16:06 - 00000020 ___SH C:\Users\Free.Jakub\ntuser.ini
2016-03-05 16:06 - 2013-11-05 12:27 - 00002207 _____ C:\Users\Free.Jakub\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\SkyDrive.lnk
2016-03-05 16:06 - 2013-10-25 15:47 - 00000000 ____D C:\Users\Free.Jakub\AppData\Local\Microsoft Help
2016-03-05 16:06 - 2013-09-17 08:45 - 00000000 ____D C:\Users\Free.Jakub\AppData\Roaming\Macromedia
2016-03-05 16:06 - 2013-09-16 13:12 - 00000000 ____D C:\Users\Free.Jakub\AppData\Roaming\ASUS WebStorage
2016-03-04 21:29 - 2016-03-04 21:29 - 09452149 _____ C:\Users\Jakubko\Downloads\Dcéram nedvíhal telefón...mp4
2016-03-04 21:27 - 2016-03-04 21:27 - 21445868 _____ C:\Users\Jakubko\Downloads\Záchrana zraneného zubra a auto-nehoda (1).mp4
2016-03-04 12:39 - 2016-03-04 12:39 - 00491312 _____ C:\Users\Jakubko\Downloads\Pozvanka_ck_OLP_XVIII_draft_8.pdf
2016-03-02 13:39 - 2016-03-02 13:39 - 00162481 _____ C:\Users\Jakubko\Desktop\VN SV-BA.pdf
2016-03-02 13:32 - 2016-03-02 13:32 - 00289928 _____ C:\Users\Jakubko\Desktop\VN BA-SV.pdf
2016-02-27 12:23 - 2016-03-09 18:48 - 00000000 ____D C:\Users\Jakubko\Desktop\Holokaust
2016-02-26 15:19 - 2016-03-06 19:50 - 00000000 ____D C:\Users\Jakubko\Desktop\KOMP
2016-02-15 21:26 - 2016-02-15 21:26 - 00000292 _____ C:\Users\Jakubko\Desktop\Pizzovníky.txt
2016-02-08 14:05 - 2016-02-15 13:57 - 00000000 ____D C:\Users\Jakubko\Desktop\Thermal
==================== One Month Modified files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2016-12-01 10:16 - 2013-09-16 13:12 - 00045056 _____ C:\Windows\SysWOW64\acovcnt.exe
2016-12-01 09:48 - 2014-08-26 14:18 - 00003490 _____ C:\Windows\System32\Tasks\AutoKMS
2016-03-09 21:54 - 2013-09-16 16:40 - 00000000 ____D C:\Users\Jakubko\AppData\Roaming\uTorrent
2016-03-09 21:32 - 2014-03-23 14:40 - 00000000 ____D C:\Users\Jakubko\AppData\Roaming\.ACEStream
2016-03-09 21:31 - 2013-10-23 17:05 - 00000000 ___HD C:\_acestream_cache_
2016-03-09 21:25 - 2014-07-12 14:20 - 00000948 _____ C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-303898890-2447975317-2344255173-1001UA.job
2016-03-09 21:07 - 2016-01-14 13:43 - 00000956 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2016-03-09 20:41 - 2012-07-26 06:37 - 00000000 ____D C:\Windows\Inf
2016-03-09 17:34 - 2016-01-14 11:22 - 00000000 ____D C:\Users\Jakubko\AppData\LocalLow\Adblock Plus for IE
2016-03-09 15:25 - 2014-07-12 14:20 - 00000926 _____ C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-303898890-2447975317-2344255173-1001Core.job
2016-03-09 09:29 - 2015-12-03 19:02 - 00107784 _____ C:\Users\Jakubko\Desktop\Dresy.xlsx
2016-03-09 09:07 - 2016-01-14 13:43 - 00000952 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2016-03-09 08:37 - 2013-09-16 10:36 - 00000000 ____D C:\Users\Jakubko\AppData\Local\Packages
2016-03-09 07:37 - 2012-08-15 17:46 - 00000739 _____ C:\Windows\SysWOW64\bscs.ini
2016-03-09 07:37 - 2012-07-26 09:12 - 00000000 ____D C:\Windows\AUInstallAgent
2016-03-09 07:36 - 2012-07-26 09:12 - 00000000 ___HD C:\Program Files\WindowsApps
2016-03-09 07:34 - 2013-03-31 09:44 - 00004268 _____ C:\Windows\SysWOW64\LOCALSERVICE.INI
2016-03-09 07:34 - 2013-03-31 09:44 - 00000043 _____ C:\Windows\SysWOW64\LOCALDEVICE.INI
2016-03-08 19:37 - 2014-06-02 20:25 - 00000000 ____D C:\Users\Jakubko\AppData\Roaming\vlc
2016-03-08 16:26 - 2016-01-15 13:58 - 00000000 ____D C:\Users\Jakubko\AppData\Roaming\Sony
2016-03-08 16:26 - 2016-01-14 19:53 - 00000000 ____D C:\Users\Jakubko\AppData\Roaming\TeamViewer
2016-03-08 16:26 - 2015-12-19 17:23 - 00000000 ____D C:\Users\Jakubko\AppData\Local\LogMeIn Hamachi
2016-03-08 16:26 - 2013-10-10 11:23 - 00000000 ____D C:\Users\Jakubko\AppData\Roaming\DAEMON Tools Lite
2016-03-08 16:09 - 2013-09-16 15:59 - 09584640 ___SH C:\Users\Jakubko\Desktop\Thumbs.db
2016-03-08 15:42 - 2013-10-13 14:38 - 06023680 ___SH C:\Users\Jakubko\Downloads\Thumbs.db
2016-03-08 15:14 - 2014-06-30 10:17 - 00004877 _____ C:\Users\Jakubko\Desktop\Neviem.txt
2016-03-08 14:38 - 2015-12-19 17:44 - 00000000 ____D C:\Program Files (x86)\EA Sports
2016-03-08 13:04 - 2013-09-17 10:46 - 00000132 _____ C:\Users\Jakubko\AppData\Roaming\Adobe PNG Format CS5 Prefs
2016-03-08 07:23 - 2013-10-29 09:22 - 00000427 _____ C:\Windows\SysWOW64\REMOTEDEVICE.INI
2016-03-07 11:42 - 2015-10-13 08:02 - 00000000 ____D C:\Users\Jakubko\Desktop\Download
2016-03-07 11:13 - 2013-03-31 09:47 - 00003056 _____ C:\Windows\System32\Tasks\ASUS P4G
2016-03-07 11:13 - 2013-03-31 09:47 - 00003028 _____ C:\Windows\System32\Tasks\ASUS USB Charger Plus
2016-03-07 11:12 - 2013-09-16 15:36 - 00000408 _____ C:\Users\Jakubko\AppData\Roaming\sp_data.sys
2016-03-06 16:04 - 2015-09-22 08:34 - 00290796 _____ C:\Users\Jakubko\Desktop\HLAS.psd
2016-03-05 16:21 - 2013-09-16 13:17 - 00003598 _____ C:\Windows\System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-303898890-2447975317-2344255173-1001
2016-03-05 16:10 - 2013-09-16 10:38 - 00000000 ____D C:\Windows\System32\Tasks\WPD
2016-03-04 17:02 - 2015-11-24 15:53 - 00000000 ____D C:\Users\Jakubko\Desktop\BC
2016-03-04 13:00 - 2015-03-18 20:13 - 00000000 ____D C:\Users\Jakubko\Desktop\Bazoš
2016-03-01 12:00 - 2012-07-26 08:28 - 00848230 _____ C:\Windows\system32\PerfStringBackup.INI
2016-02-26 21:07 - 2015-10-03 10:47 - 00000000 ____D C:\Users\Jakubko\Desktop\BORDEL
2016-02-20 07:10 - 2016-01-14 13:44 - 00002226 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2016-02-18 10:53 - 2014-12-05 17:04 - 00000000 ____D C:\Users\Jakubko\Desktop\3. ročník
2016-02-16 14:27 - 2016-01-14 19:51 - 00000000 ____D C:\Program Files (x86)\TeamViewer
2016-02-15 16:44 - 2016-01-25 08:45 - 00000000 ____D C:\Users\Jakubko\Desktop\TO
2016-02-15 12:08 - 2016-01-12 15:51 - 00000000 ____D C:\Users\Jakubko\Desktop\List
2016-02-14 12:17 - 2014-10-16 16:33 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java
2016-02-14 12:17 - 2014-10-16 16:33 - 00000000 ____D C:\Program Files (x86)\Java
2016-02-14 12:17 - 2013-09-26 09:36 - 00000000 ____D C:\ProgramData\Oracle
2016-02-14 12:16 - 2015-08-28 17:26 - 00000000 ____D C:\Users\Jakubko\.oracle_jre_usage
2016-02-14 12:14 - 2014-10-16 16:33 - 00097888 _____ (Oracle Corporation) C:\Windows\SysWOW64\WindowsAccessBridge-32.dll
2016-02-14 12:05 - 2014-01-03 23:59 - 05061280 _____ C:\Windows\system32\FNTCACHE.DAT
2016-02-14 12:05 - 2012-07-26 08:22 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2016-02-14 12:04 - 2012-07-26 06:26 - 00524288 ___SH C:\Windows\system32\config\BBI
2016-02-14 12:02 - 2012-07-26 09:12 - 00000000 ____D C:\Windows\system32\NDF
==================== Files in the root of some directories =======
2013-11-11 20:43 - 2014-07-20 13:08 - 0000132 _____ () C:\Users\Jakubko\AppData\Roaming\Adobe GIF Format CS5 Prefs
2013-09-17 10:46 - 2016-03-08 13:04 - 0000132 _____ () C:\Users\Jakubko\AppData\Roaming\Adobe PNG Format CS5 Prefs
2014-04-25 14:22 - 2014-04-25 15:05 - 0000000 _____ () C:\Users\Jakubko\AppData\Roaming\FileIn.cns
2014-04-25 14:22 - 2014-04-25 15:05 - 0000000 _____ () C:\Users\Jakubko\AppData\Roaming\FileOut.cns
2013-09-16 15:36 - 2016-03-07 11:12 - 0000408 _____ () C:\Users\Jakubko\AppData\Roaming\sp_data.sys
2013-11-12 11:44 - 2016-01-15 16:42 - 0001456 _____ () C:\Users\Jakubko\AppData\Local\Adobe Save for Web 12.0 Prefs
2014-10-31 19:48 - 2014-10-31 19:48 - 0007605 _____ () C:\Users\Jakubko\AppData\Local\Resmon.ResmonCfg
2016-03-09 16:33 - 2016-03-09 16:33 - 0000017 _____ () C:\ProgramData\adaware-installer-reboot-required.tmp
2012-11-23 14:06 - 2012-09-07 12:40 - 0000256 _____ () C:\ProgramData\SetStretch.cmd
2012-11-23 14:06 - 2009-07-22 11:04 - 0024576 _____ () C:\ProgramData\SetStretch.exe
2012-11-23 14:06 - 2012-09-07 12:37 - 0000103 _____ () C:\ProgramData\SetStretch.VBS
==================== Bamital & volsnap =================
(There is no automatic fix for files that do not pass verification.)
C:\Windows\system32\winlogon.exe => File is digitally signed
C:\Windows\system32\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\system32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\system32\services.exe => File is digitally signed
C:\Windows\system32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\system32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\system32\rpcss.dll => File is digitally signed
C:\Windows\system32\dnsapi.dll => File is digitally signed
C:\Windows\SysWOW64\dnsapi.dll => File is digitally signed
C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed
LastRegBack: 2016-03-07 15:12
==================== End of FRST.txt ============================
Posielam scan FRST:
Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version:05-03-2016 01
Ran by Jakubko (administrator) on JAKUB (09-03-2016 21:54:23)
Running from C:\Users\Jakubko\Downloads
Loaded Profiles: Jakubko & (Available Profiles: Jakubko & Free)
Platform: Windows 8 (X64) Language: Slovenčina (Slovensko)
Internet Explorer Version 10 (Default browser: Chrome)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/33 ... scan-tool/
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(ESET) C:\Program Files\ESET\ESET Smart Security\x86\ekrn.exe
(LogMeIn, Inc.) C:\Program Files (x86)\LogMeIn Hamachi\LMIGuardianSvc.exe
(TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe
(LogMeIn Inc.) C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2.exe
(Microsoft Corporation) C:\Windows\System32\alg.exe
(ASUSTek Computer Inc.) C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\AsLdrSrv.exe
(ASUS) C:\Program Files (x86)\ASUS\ATK Package\ATKGFNEX\GFNEXSrv.exe
(IVT Corporation) C:\Program Files (x86)\Ralink Corporation\Ralink Bluetooth Stack\BlueSoleilCS.exe
(IVT Corporation) C:\Program Files (x86)\Ralink Corporation\Ralink Bluetooth Stack\BsHelpCS.exe
(Intel(R) Corporation) C:\Program Files\Intel\iCLS Client\HeciServer.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\Jhi_service.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
(Adobe Systems, Incorporated) C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGSService.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(ESET) C:\Program Files\ESET\ESET Smart Security\egui.exe
(ASUSTek Computer Inc.) C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControl.exe
(ASUSTeK Computer Inc.) C:\Windows\System32\FBAgent.exe
(ASUSTek Computer Inc.) C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\KBFiltr.exe
(ASUSTek Computer Inc.) C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe
(ASUSTek Computer Inc.) C:\Program Files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe
(Logitech Inc.) C:\Program Files\Logitech\Gaming Software\LWEMon.exe
(ESET) C:\Program Files\ESET\ESET Smart Security\egui.exe
(Filipe Lourenço) C:\Program Files (x86)\BatteryCare\BatteryCare.exe
(Flux Software LLC) C:\Users\Jakubko\AppData\Local\FluxSoftware\Flux\flux.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(ASUS) C:\Program Files (x86)\ASUS\Splendid\ACMON.exe
(ASUSTeK) C:\Windows\SysWOW64\ACEngSvr.exe
(Intel Corporation) C:\Windows\System32\igfxpers.exe
(IVT Corporation) C:\Program Files (x86)\Ralink Corporation\Ralink Bluetooth Stack\BtTray.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
(ASUS) C:\Program Files\ASUS\P4G\BatteryLife.exe
(ASUSTek Computer Inc.) C:\Program Files (x86)\ASUS\USBChargerPlus\USBChargerPlus.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(BitTorrent Inc.) C:\Users\Jakubko\AppData\Roaming\uTorrent\uTorrent.exe
(BitTorrent Inc.) C:\Users\Jakubko\AppData\Roaming\uTorrent\updates\3.4.5_41865\utorrentie.exe
(BitTorrent Inc.) C:\Users\Jakubko\AppData\Roaming\uTorrent\updates\3.4.5_41865\utorrentie.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
() C:\Users\Jakubko\AppData\Roaming\ACEStream\engine\ace_engine.exe
() C:\Users\Jakubko\AppData\Roaming\ACEStream\updater\ace_update.exe
(Malwarebytes) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe
(Malwarebytes) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe
(Malwarebytes) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbam.exe
(Microsoft Corporation) C:\Windows\SysWOW64\notepad.exe
(Microsoft Corporation) C:\Windows\System32\rundll32.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
==================== Registry (Whitelisted) ===========================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [AdobeAAMUpdater-1.0] => C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [508240 2015-08-05] (Adobe Systems Incorporated)
HKLM\...\Run: [Start WingMan Profiler] => C:\Program Files\Logitech\Gaming Software\LWEMon.exe [190536 2010-06-14] (Logitech Inc.)
HKLM\...\Run: [egui] => C:\Program Files\ESET\ESET Smart Security\egui.exe [5595848 2015-07-08] (ESET)
HKLM\...\Run: [] => [X]
HKLM\...\Run: [AdAwareTray] => C:\Program Files\Lavasoft\Ad-Aware Antivirus\Ad-Aware Antivirus\11.10.767.8917\AdAwareTray.exe [9581280 2016-01-28] ()
HKLM-x32\...\Run: [SwitchBoard] => C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [517096 2010-02-19] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [AdobeCS5ServiceManager] => C:\Program Files (x86)\Common Files\Adobe\CS5ServiceManager\CS5ServiceManager.exe [402432 2010-07-22] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [958576 2013-04-04] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [AdobeCS6ServiceManager] => C:\Program Files (x86)\Common Files\Adobe\CS6ServiceManager\CS6ServiceManager.exe [1075296 2013-04-25] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [LogMeIn Hamachi Ui] => C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe [5565448 2015-11-12] (LogMeIn Inc.)
HKLM-x32\...\Run: [BlueStacks Agent] => C:\Program Files (x86)\BlueStacks\HD-Agent.exe
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [594992 2016-01-29] (Oracle Corporation)
Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation)
HKU\S-1-5-21-303898890-2447975317-2344255173-1001\...\Run: [RocketDock] => "C:\Program Files\RocketDock\RocketDock.exe"
HKU\S-1-5-21-303898890-2447975317-2344255173-1001\...\Run: [DU Meter] => "C:\Program Files (x86)\DU Meter\DUMeter.exe" /autostart
HKU\S-1-5-21-303898890-2447975317-2344255173-1001\...\Run: [AdobeBridge] => [X]
HKU\S-1-5-21-303898890-2447975317-2344255173-1001\...\Run: [BatteryCare] => C:\Program Files (x86)\BatteryCare\BatteryCare.exe [796160 2015-10-25] (Filipe Lourenço)
HKU\S-1-5-21-303898890-2447975317-2344255173-1001\...\Run: [CCleaner Monitoring] => C:\Program Files\CCleaner\CCleaner64.exe [8461224 2015-09-16] (Piriform Ltd)
HKU\S-1-5-21-303898890-2447975317-2344255173-1001\...\RunOnce: [Uninstall C:\Users\Jakubko\AppData\Local\Microsoft\SkyDrive\16.4.6013.0910\amd64] => C:\Windows\system32\cmd.exe /q /c rmdir /s /q "C:\Users\Jakubko\AppData\Local\Microsoft\SkyDrive\16.4.6013.0910\amd64"
HKU\S-1-5-21-303898890-2447975317-2344255173-1001\...\RunOnce: [Uninstall C:\Users\Jakubko\AppData\Local\Microsoft\SkyDrive\17.0.2015.0811\amd64] => C:\Windows\system32\cmd.exe /q /c rmdir /s /q "C:\Users\Jakubko\AppData\Local\Microsoft\SkyDrive\17.0.2015.0811\amd64"
HKU\S-1-5-21-303898890-2447975317-2344255173-1001\...\MountPoints2: {303d40f4-261a-11e5-bec4-b8763f0ffd04} - "G:\LG_PC_Programs.exe"
HKU\S-1-5-21-303898890-2447975317-2344255173-1001\...\MountPoints2: {412c5d44-2201-11e3-be77-b8763f0ffd04} - "G:\HTC_Sync_Manager_PC.exe"
HKU\S-1-5-21-303898890-2447975317-2344255173-1001\...\MountPoints2: {692bc9db-5d11-11e3-be7a-b8763f0ffd04} - "G:\HTC_Sync_Manager_PC.exe"
HKU\S-1-5-21-303898890-2447975317-2344255173-1001\...\MountPoints2: {6e1c7d43-2f64-11e3-be77-b8763f0ffd04} - "F:\autorun.exe"
HKU\S-1-5-21-303898890-2447975317-2344255173-1001\...\MountPoints2: {846c8ad3-31ec-11e3-be78-b8763f0ffd04} - "E:\Autorun.exe"
HKU\S-1-5-21-303898890-2447975317-2344255173-1001\Control Panel\Desktop\\SCRNSAVE.EXE ->
HKU\S-1-5-21-303898890-2447975317-2344255173-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\Run: [RocketDock] => "C:\Program Files\RocketDock\RocketDock.exe"
HKU\S-1-5-21-303898890-2447975317-2344255173-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\Run: [DU Meter] => "C:\Program Files (x86)\DU Meter\DUMeter.exe" /autostart
HKU\S-1-5-21-303898890-2447975317-2344255173-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\Run: [AdobeBridge] => [X]
HKU\S-1-5-21-303898890-2447975317-2344255173-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\Run: [BatteryCare] => C:\Program Files (x86)\BatteryCare\BatteryCare.exe [796160 2015-10-25] (Filipe Lourenço)
HKU\S-1-5-21-303898890-2447975317-2344255173-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\Run: [CCleaner Monitoring] => C:\Program Files\CCleaner\CCleaner64.exe [8461224 2015-09-16] (Piriform Ltd)
HKU\S-1-5-21-303898890-2447975317-2344255173-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\RunOnce: [Uninstall C:\Users\Jakubko\AppData\Local\Microsoft\SkyDrive\16.4.6013.0910\amd64] => C:\Windows\system32\cmd.exe /q /c rmdir /s /q "C:\Users\Jakubko\AppData\Local\Microsoft\SkyDrive\16.4.6013.0910\amd64"
HKU\S-1-5-21-303898890-2447975317-2344255173-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\RunOnce: [Uninstall C:\Users\Jakubko\AppData\Local\Microsoft\SkyDrive\17.0.2015.0811\amd64] => C:\Windows\system32\cmd.exe /q /c rmdir /s /q "C:\Users\Jakubko\AppData\Local\Microsoft\SkyDrive\17.0.2015.0811\amd64"
HKU\S-1-5-21-303898890-2447975317-2344255173-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\MountPoints2: {303d40f4-261a-11e5-bec4-b8763f0ffd04} - "G:\LG_PC_Programs.exe"
HKU\S-1-5-21-303898890-2447975317-2344255173-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\MountPoints2: {412c5d44-2201-11e3-be77-b8763f0ffd04} - "G:\HTC_Sync_Manager_PC.exe"
HKU\S-1-5-21-303898890-2447975317-2344255173-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\MountPoints2: {692bc9db-5d11-11e3-be7a-b8763f0ffd04} - "G:\HTC_Sync_Manager_PC.exe"
HKU\S-1-5-21-303898890-2447975317-2344255173-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\MountPoints2: {6e1c7d43-2f64-11e3-be77-b8763f0ffd04} - "F:\autorun.exe"
HKU\S-1-5-21-303898890-2447975317-2344255173-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\MountPoints2: {846c8ad3-31ec-11e3-be78-b8763f0ffd04} - "E:\Autorun.exe"
HKU\S-1-5-21-303898890-2447975317-2344255173-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\Control Panel\Desktop\\SCRNSAVE.EXE ->
ShellIconOverlayIdentifiers: ["DropboxExt1"] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Jakubko\AppData\Roaming\Dropbox\bin\DropboxExt64.25.dll [2015-02-11] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: ["DropboxExt2"] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Jakubko\AppData\Roaming\Dropbox\bin\DropboxExt64.25.dll [2015-02-11] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: ["DropboxExt3"] -> {FB314EDD-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Jakubko\AppData\Roaming\Dropbox\bin\DropboxExt64.25.dll [2015-02-11] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: ["DropboxExt4"] -> {FB314EDE-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Jakubko\AppData\Roaming\Dropbox\bin\DropboxExt64.25.dll [2015-02-11] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: ["DropboxExt5"] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Jakubko\AppData\Roaming\Dropbox\bin\DropboxExt64.25.dll [2015-02-11] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: ["DropboxExt6"] -> {FB314EDF-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Jakubko\AppData\Roaming\Dropbox\bin\DropboxExt64.25.dll [2015-02-11] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: ["DropboxExt7"] -> {FB314EDC-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Jakubko\AppData\Roaming\Dropbox\bin\DropboxExt64.25.dll [2015-02-11] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: ["DropboxExt8"] -> {FB314EE0-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Jakubko\AppData\Roaming\Dropbox\bin\DropboxExt64.25.dll [2015-02-11] (Dropbox, Inc.)
Startup: C:\Users\Jakubko\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk [2015-02-25]
ShortcutTarget: Dropbox.lnk -> C:\Users\Jakubko\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
Hosts: There are more than one entry in Hosts. See Hosts section of Addition.txt
Tcpip\Parameters: [DhcpNameServer] 158.195.6.2 158.195.6.3 158.195.4.3
Tcpip\..\Interfaces\{B19DAFF3-11D7-491A-B8B8-3C62919F0E54}: [DhcpNameServer] 158.195.6.2 158.195.6.3 158.195.4.3
Internet Explorer:
==================
HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer: Restriction <======= ATTENTION
HKU\S-1-5-21-303898890-2447975317-2344255173-1001\Software\Microsoft\Internet Explorer\Main,Start Page = about:Tabs
HKU\S-1-5-21-303898890-2447975317-2344255173-1001\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://asus13.msn.com
HKU\S-1-5-21-303898890-2447975317-2344255173-1001\Software\Microsoft\Internet Explorer\Main,Search Bar = hxxp://www.google.com/ie
HKU\S-1-5-21-303898890-2447975317-2344255173-1001\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://www.google.com/ie
HKU\S-1-5-21-303898890-2447975317-2344255173-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\Software\Microsoft\Internet Explorer\Main,Start Page = about:Tabs
HKU\S-1-5-21-303898890-2447975317-2344255173-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://asus13.msn.com
HKU\S-1-5-21-303898890-2447975317-2344255173-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\Software\Microsoft\Internet Explorer\Main,Search Bar = hxxp://www.google.com/ie
HKU\S-1-5-21-303898890-2447975317-2344255173-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://www.google.com/ie
HKU\S-1-5-21-303898890-2447975317-2344255173-1005-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://asus13.msn.com
HKU\S-1-5-21-303898890-2447975317-2344255173-1005-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://asus13.msn.com
SearchScopes: HKU\S-1-5-21-303898890-2447975317-2344255173-1001 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-21-303898890-2447975317-2344255173-1001 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-21-303898890-2447975317-2344255173-1001 -> {6A1806CD-94D4-4689-BA73-E35EA1EA9990} URL = hxxp://www.google.com/search?q={sear
SearchScopes: HKU\S-1-5-21-303898890-2447975317-2344255173-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-21-303898890-2447975317-2344255173-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-21-303898890-2447975317-2344255173-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0 -> {6A1806CD-94D4-4689-BA73-E35EA1EA9990} URL = hxxp://www.google.com/search?q={sear
BHO: Lync Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files\Microsoft Office\Office15\OCHelper.dll [2012-10-01] (Microsoft Corporation)
BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office\Office15\URLREDIR.DLL [2012-10-01] (Microsoft Corporation)
BHO: Microsoft SkyDrive Pro Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files\Microsoft Office\Office15\GROOVEEX.DLL [2012-10-01] (Microsoft Corporation)
BHO-x32: Lync Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files (x86)\Microsoft Office\Office15\OCHelper.dll [2012-10-01] (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_73\bin\ssv.dll [2016-02-14] (Oracle Corporation)
BHO-x32: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files (x86)\Microsoft Office\Office15\URLREDIR.DLL [2012-10-01] (Microsoft Corporation)
BHO-x32: Microsoft SkyDrive Pro Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files (x86)\Microsoft Office\Office15\GROOVEEX.DLL [2012-10-01] (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_73\bin\jp2ssv.dll [2016-02-14] (Oracle Corporation)
Handler: osf - {D924BDC6-C83A-4BD5-90D0-095128A113D1} - C:\Program Files\Microsoft Office\Office15\MSOSB.DLL [2012-10-01] (Microsoft Corporation)
FireFox:
========
FF ProfilePath: C:\Users\Jakubko\AppData\Roaming\Mozilla\Firefox\Profiles\vidg21l8.default
FF Plugin: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~1\MICROS~1\Office15\NPSPWRAP.DLL [2012-10-01] (Microsoft Corporation)
FF Plugin: adobe.com/AdobeAAMDetect -> C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\CCM\Utilities\npAdobeAAMDetect64.dll [2015-08-06] (Adobe Systems)
FF Plugin: adobe.com/AdobeExManDetect -> C:\Program Files (x86)\Adobe\Adobe Extension Manager CS6\Win64Plugin\npAdobeExManDetectX64.dll [2013-12-02] (Adobe Systems)
FF Plugin-x32: @google.com/npPicasa3,version=3.0.0 -> C:\Program Files (x86)\Google\Picasa3\npPicasa3.dll [2015-02-13] (Google, Inc.)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=2.1.42 -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll [2012-06-06] (Intel Corporation)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll [2012-06-06] (Intel Corporation)
FF Plugin-x32: @java.com/DTPlugin,version=11.73.2 -> C:\Program Files (x86)\Java\jre1.8.0_73\bin\dtplugin\npDeployJava1.dll [2016-02-14] (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=11.73.2 -> C:\Program Files (x86)\Java\jre1.8.0_73\bin\plugin2\npjp2.dll [2016-02-14] (Oracle Corporation)
FF Plugin-x32: @microsoft.com/Lync,version=15.0 -> C:\Program Files (x86)\Mozilla Firefox\plugins\npmeetingjoinpluginoc.dll [2012-10-01] (Microsoft Corporation)
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files (x86)\Microsoft Silverlight\5.1.40416.0\npctrl.dll [2015-04-15] ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~2\MICROS~1\Office15\NPSPWRAP.DLL [2012-10-01] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=16.4.3505.0912 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2012-09-12] (Microsoft Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.29.5\npGoogleUpdate3.dll [2016-02-02] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.29.5\npGoogleUpdate3.dll [2016-02-02] (Google Inc.)
FF Plugin-x32: @veetle.com/veetleCorePlugin,version=0.9.19 -> C:\Program Files (x86)\Veetle\plugins\npVeetle.dll [2012-01-14] (Veetle Inc)
FF Plugin-x32: @veetle.com/veetlePlayerPlugin,version=0.9.18 -> C:\Program Files (x86)\Veetle\Player\npvlc.dll [2012-01-14] (Veetle Inc)
FF Plugin-x32: @videolan.org/vlc,version=2.0.5 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2012-12-13] (VideoLAN)
FF Plugin-x32: @videolan.org/vlc,version=2.1.0 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2012-12-13] (VideoLAN)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll [2013-09-03] (Adobe Systems Inc.)
FF Plugin-x32: adobe.com/AdobeAAMDetect -> C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\CCM\Utilities\npAdobeAAMDetect32.dll [2015-08-06] (Adobe Systems)
FF Plugin-x32: adobe.com/AdobeExManDetect -> C:\Program Files (x86)\Adobe\Adobe Extension Manager CS6\npAdobeExManDetectX86.dll [2013-12-02] (Adobe Systems)
FF Plugin HKU\S-1-5-21-303898890-2447975317-2344255173-1001: @acestream.net/acestreamplugin,version=2.2.2-next -> C:\Users\Jakubko\AppData\Roaming\ACEStream\player\npace_plugin.dll [2014-07-09] (Innovative Digital Technologies)
FF Plugin HKU\S-1-5-21-303898890-2447975317-2344255173-1001: @Skype Limited.com/Facebook Video Calling Plugin -> C:\Users\Jakubko\AppData\Local\Facebook\Video\Skype\npFacebookVideoCalling.dll [2014-07-24] (Skype Limited)
FF Plugin HKU\S-1-5-21-303898890-2447975317-2344255173-1001: @unity3d.com/UnityPlayer,version=1.0 -> C:\Users\Jakubko\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll [2009-11-30] (Unity Technologies ApS)
FF Plugin HKU\S-1-5-21-303898890-2447975317-2344255173-1001: anvisoft.com/AdblockPlugin -> C:\ProgramData\Anvisoft\Anvi Smart Defender 2\extensions\npAdblockPlugin.dll [No File]
FF Plugin HKU\S-1-5-21-303898890-2447975317-2344255173-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0: @acestream.net/acestreamplugin,version=2.2.2-next -> C:\Users\Jakubko\AppData\Roaming\ACEStream\player\npace_plugin.dll [2014-07-09] (Innovative Digital Technologies)
FF Plugin HKU\S-1-5-21-303898890-2447975317-2344255173-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0: @Skype Limited.com/Facebook Video Calling Plugin -> C:\Users\Jakubko\AppData\Local\Facebook\Video\Skype\npFacebookVideoCalling.dll [2014-07-24] (Skype Limited)
FF Plugin HKU\S-1-5-21-303898890-2447975317-2344255173-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0: @unity3d.com/UnityPlayer,version=1.0 -> C:\Users\Jakubko\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll [2009-11-30] (Unity Technologies ApS)
FF Plugin HKU\S-1-5-21-303898890-2447975317-2344255173-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0: anvisoft.com/AdblockPlugin -> C:\ProgramData\Anvisoft\Anvi Smart Defender 2\extensions\npAdblockPlugin.dll [No File]
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npMeetingJoinPluginOC.dll [2012-10-01] (Microsoft Corporation)
FF Extension: Gmail panel - C:\Users\Jakubko\AppData\Roaming\Mozilla\Firefox\Profiles\vidg21l8.default\extensions\gmail_panel@alejandrobrizuela.com.ar.xpi [2016-01-14]
FF Extension: Fasterfox - C:\Users\Jakubko\AppData\Roaming\Mozilla\Firefox\Profiles\vidg21l8.default\extensions\{c36177c0-224a-11da-8cd6-0800200c9a91}.xpi [2016-01-14]
FF Extension: Adblock Plus - C:\Users\Jakubko\AppData\Roaming\Mozilla\Firefox\Profiles\vidg21l8.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2016-01-14]
FF HKLM\...\Thunderbird\Extensions: [eplgTb@eset.com] - C:\Program Files\ESET\ESET Smart Security\Mozilla Thunderbird => not found
FF HKLM-x32\...\Thunderbird\Extensions: [msktbird@mcafee.com] - C:\Program Files\McAfee\MSK => not found
FF HKLM-x32\...\Thunderbird\Extensions: [eplgTb@eset.com] - C:\Program Files\ESET\ESET Smart Security\Mozilla Thunderbird => not found
FF HKU\S-1-5-21-303898890-2447975317-2344255173-1001\...\Firefox\Extensions: [magicplayer@torrentstream.org] - C:\Users\Jakubko\AppData\Roaming\ACEStream\extensions\firefox\magicplayer@torrentstream.org
FF Extension: TS Magic Player - C:\Users\Jakubko\AppData\Roaming\ACEStream\extensions\firefox\magicplayer@torrentstream.org [2014-09-13] [not signed]
FF HKU\S-1-5-21-303898890-2447975317-2344255173-1001\...\SeaMonkey\Extensions: [mozilla_cc2@internetdownloadmanager.com] - C:\Program Files (x86)\Internet Download Manager\idmmzcc2.xpi => not found
FF HKU\S-1-5-21-303898890-2447975317-2344255173-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\Firefox\Extensions: [magicplayer@torrentstream.org] - C:\Users\Jakubko\AppData\Roaming\ACEStream\extensions\firefox\magicplayer@torrentstream.org
FF HKU\S-1-5-21-303898890-2447975317-2344255173-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\SeaMonkey\Extensions: [mozilla_cc2@internetdownloadmanager.com] - C:\Program Files (x86)\Internet Download Manager\idmmzcc2.xpi => not found
Chrome:
=======
CHR Plugin: (Shockwave Flash) - C:\Program Files (x86)\Google\Chrome\Application\47.0.2526.106\PepperFlash\pepflashplayer.dll => No File
CHR Plugin: (Native Client) - C:\Program Files (x86)\Google\Chrome\Application\48.0.2564.116\ppGoogleNaClPluginChrome.dll => No File
CHR Plugin: (Chrome PDF Viewer) - C:\Program Files (x86)\Google\Chrome\Application\48.0.2564.116\pdf.dll => No File
CHR Plugin: (Adobe Acrobat) - C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Browser\nppdf32.dll (Adobe Systems Inc.)
CHR Plugin: (Google Update) - C:\Program Files (x86)\Google\Update\1.3.21.153\npGoogleUpdate3.dll => No File
CHR Plugin: (Intel® Identity Protection Technology) - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll (Intel Corporation)
CHR Plugin: (Intel® Identity Protection Technology) - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll (Intel Corporation)
CHR Plugin: (Photo Gallery) - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
CHR Plugin: (McAfee SecurityCenter) - c:\progra~2\mcafee\msc\npmcsn~1.dll => No File
CHR Profile: C:\Users\Jakubko\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (Dokumenty Google) - C:\Users\Jakubko\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2016-01-14]
CHR Extension: (YouTube) - C:\Users\Jakubko\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2016-01-14]
CHR Extension: (Google Search) - C:\Users\Jakubko\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2016-01-14]
CHR Extension: (Gmail™ Notifier) - C:\Users\Jakubko\AppData\Local\Google\Chrome\User Data\Default\Extensions\dcjichoefijpinlfnjghokpkojhlhkgl [2016-02-05]
CHR Extension: (Dokumenty Google v režime offline) - C:\Users\Jakubko\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2016-01-14]
CHR Extension: (AdBlock) - C:\Users\Jakubko\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom [2016-02-21]
CHR Extension: (AS Magic Player) - C:\Users\Jakubko\AppData\Local\Google\Chrome\User Data\Default\Extensions\mfhnkgpdlogbknkhlgdjlejeljbhflim [2016-01-18]
CHR Extension: (F.B Purity-Clean Up Facebook) - C:\Users\Jakubko\AppData\Local\Google\Chrome\User Data\Default\Extensions\ncdlagniojmheiklojdcpdaeepochckl [2016-03-04]
CHR Extension: (Gmail) - C:\Users\Jakubko\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2016-01-14]
CHR HKLM\...\Chrome\Extension: [ngpampappnmepgilojfohadhhmbhlaek] - C:\Program Files (x86)\Internet Download Manager\IDMGCExt.crx <not found>
CHR HKU\S-1-5-21-303898890-2447975317-2344255173-1001\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [kpckgflgdapkpabemgkielbefdildaio] - C:\Users\Jakubko\AppData\Roaming\ACEStream\extensions\chrome_new\magicplayer.crx [2014-01-28]
CHR HKU\S-1-5-21-303898890-2447975317-2344255173-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [kpckgflgdapkpabemgkielbefdildaio] - C:\Users\Jakubko\AppData\Roaming\ACEStream\extensions\chrome_new\magicplayer.crx [2014-01-28]
CHR HKLM-x32\...\Chrome\Extension: [lhmiofmipcpmhgihiecmpiekcacigpgb] - C:\ProgramData\Anvisoft\Anvi Smart Defender 2\extensions\chrome.crx <not found>
StartMenuInternet: chrome.exe - C:\Users\Jakubko\AppData\Local\Google\Chrome\Application\chrome.exe
==================== Services (Whitelisted) ========================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R2 AGSService; C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGSService.exe [2020056 2016-02-09] (Adobe Systems, Incorporated)
R3 BlueSoleilCS; C:\Program Files (x86)\Ralink Corporation\Ralink Bluetooth Stack\BlueSoleilCS.exe [1578496 2012-08-14] (IVT Corporation) [File not signed]
R3 BsHelpCS; C:\Program Files (x86)\Ralink Corporation\Ralink Bluetooth Stack\BsHelpCS.exe [138752 2012-08-14] (IVT Corporation) [File not signed]
R2 ekrn; C:\Program Files\ESET\ESET Smart Security\x86\ekrn.exe [1353720 2015-07-08] (ESET)
S3 IDriverT; C:\Program Files (x86)\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe [69632 2005-04-04] (Macrovision Corporation) [File not signed]
R3 Intel(R) ME Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe [129856 2012-06-27] (Intel Corporation)
R3 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [166720 2012-06-25] (Intel Corporation)
S2 LavasoftAdAwareService11; C:\Program Files\Lavasoft\Ad-Aware Antivirus\Ad-Aware Antivirus\11.10.767.8917\AdAwareService.exe [712432 2016-01-28] ()
R2 LMIGuardianSvc; C:\Program Files (x86)\LogMeIn Hamachi\LMIGuardianSvc.exe [417552 2015-11-12] (LogMeIn, Inc.)
R2 MBAMScheduler; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe [1513784 2015-10-05] (Malwarebytes)
R2 MBAMService; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe [1135416 2015-10-05] (Malwarebytes)
S3 Origin Client Service; C:\Program Files (x86)\Origin\OriginClientService.exe [2057736 2015-09-08] (Electronic Arts)
S3 SwitchBoard; C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [517096 2010-02-19] (Adobe Systems Incorporated) [File not signed]
R2 TeamViewer; C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe [6889232 2015-12-14] (TeamViewer GmbH)
S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [16048 2013-07-02] (Microsoft Corporation)
S2 mcbootdelaystartsvc; "C:\Program Files\Common Files\mcafee\McSvcHost\McSvHost.exe" /McCoreSvc [X]
===================== Drivers (Whitelisted) ==========================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R3 Apowersoft_AudioDevice; C:\Windows\system32\drivers\Apowersoft_AudioDevice.sys [31920 2014-04-09] (Wondershare)
S3 ATP; C:\Windows\System32\drivers\AsusTP.sys [65784 2013-01-16] (ASUS Corporation)
S3 avc3; C:\Windows\System32\DRIVERS\avc3.sys [1600512 2016-01-05] (BitDefender)
R3 avchv; C:\Windows\system32\DRIVERS\avchv.sys [282000 2016-01-05] (BitDefender)
S3 avckf; C:\Windows\System32\DRIVERS\avckf.sys [775424 2016-01-05] (BitDefender)
R1 BdfNdisf; C:\Program Files\Lavasoft\Ad-Aware Antivirus\Firewall Engine\1.6.0.0\Drivers\bdfndisf6.sys [97816 2015-01-06] (BitDefender LLC)
R1 bdfwfpf; C:\Program Files\Lavasoft\Ad-Aware Antivirus\Firewall Engine\1.6.0.0\Drivers\bdfwfpf.sys [107080 2015-01-06] (BitDefender LLC)
U5 BlueletAudio; C:\Windows\System32\Drivers\BlueletAudio.sys [34912 2012-06-15] (Ralink Corporation.)
R3 BtAudioBusSrv; C:\Windows\System32\Drivers\BtAudioBus.sys [23136 2012-06-15] (IVT Corporation)
U4 BthA2DP; C:\Windows\system32\drivers\BthA2DP.sys [117632 2013-06-01] (Microsoft Corporation)
R3 BthL2caScoIfSrv; C:\Windows\System32\Drivers\BtL2caScoIf.sys [56904 2012-07-19] (Ralink Corporation)
R3 btUrbFilterDrv; C:\Windows\System32\Drivers\IvtUrbBtFlt.sys [48736 2012-08-14] (Ralink Corporation)
R1 dtsoftbus01; C:\Windows\System32\drivers\dtsoftbus01.sys [283064 2013-10-10] (Disc Soft Ltd)
R1 eamonm; C:\Windows\System32\DRIVERS\eamonm.sys [255240 2015-07-14] (ESET)
S0 ebdrv; C:\Windows\System32\drivers\evbda.sys [3265256 2012-11-23] (Broadcom Corporation)
R0 edevmon; C:\Windows\System32\DRIVERS\edevmon.sys [251632 2015-07-14] (ESET)
R1 ehdrv; C:\Windows\system32\DRIVERS\ehdrv.sys [178520 2015-07-14] (ESET)
R2 epfw; C:\Windows\system32\DRIVERS\epfw.sys [231520 2015-07-14] (ESET)
R1 EpfwLWF; C:\Windows\system32\DRIVERS\EpfwLWF.sys [53360 2015-07-14] (ESET)
R0 epfwwfp; C:\Windows\System32\DRIVERS\epfwwfp.sys [72400 2015-07-14] (ESET)
S3 gzflt; C:\Program Files\Lavasoft\Ad-Aware Antivirus\Antimalware Engine\3.0.99.0\gzflt.sys [155912 2015-12-09] (BitDefender LLC)
R3 Hamachi; C:\Windows\system32\DRIVERS\Hamdrv.sys [45680 2015-11-12] (LogMeIn Inc.)
R3 kbfiltr; C:\Windows\System32\drivers\kbfiltr.sys [14992 2012-08-02] ( )
R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25816 2015-10-05] (Malwarebytes)
R3 MBAMSwissArmy; C:\Windows\system32\drivers\MBAMSwissArmy.sys [192216 2016-03-09] (Malwarebytes)
R3 MBAMWebAccessControl; C:\Windows\system32\drivers\mwac.sys [64216 2015-10-05] (Malwarebytes Corporation)
R3 rtbth; C:\Windows\System32\drivers\rtbth.sys [695392 2012-08-14] (Ralink Technology, Corp.)
R0 sptd; C:\Windows\System32\Drivers\sptd.sys [564824 2013-10-10] (Duplex Secure Ltd.)
S3 Trufos; C:\Windows\System32\DRIVERS\Trufos.sys [452040 2015-12-09] (BitDefender S.R.L.)
U5 UnlockerDriver5; C:\Program Files\Unlocker\UnlockerDriver5.sys [12352 2010-07-01] ()
S3 WdBoot; C:\Windows\system32\drivers\WdBoot.sys [36288 2013-07-02] (Microsoft Corporation)
S3 WdFilter; C:\Windows\system32\drivers\WdFilter.sys [247216 2013-07-01] (Microsoft Corporation)
S3 WinRing0_1_2_0; C:\Program Files (x86)\BatteryCare\WinRing0x64.sys [14544 2014-03-22] (OpenLibSys.org)
U3 amy5qqob; C:\Windows\System32\Drivers\amy5qqob.sys [0 ] (Intel Corporation) <==== ATTENTION (zero byte File/Folder)
U5 BlueletAudio; C:\Windows\SysWOW64\Drivers\BlueletAudio.sys [34912 2012-06-15] (Ralink Corporation.)
S3 DUMeterDrv; \??\C:\Program Files (x86)\DU Meter\DUMETR64.SYS [X]
U0 msahci; no ImagePath
S3 vmci; \SystemRoot\System32\drivers\vmci.sys [X]
S3 VMnetAdapter; \SystemRoot\system32\DRIVERS\vmnetadapter.sys [X]
==================== NetSvcs (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
==================== One Month Created files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2016-03-09 21:54 - 2016-03-09 21:56 - 00034731 _____ C:\Users\Jakubko\Downloads\FRST.txt
2016-03-09 21:53 - 2016-03-09 21:54 - 00000000 ____D C:\FRST
2016-03-09 21:53 - 2016-03-09 21:53 - 02374144 _____ (Farbar) C:\Users\Jakubko\Downloads\FRST64.exe
2016-03-09 21:43 - 2016-03-09 21:43 - 00388608 _____ (Trend Micro Inc.) C:\Users\Jakubko\Downloads\hijackthis.exe
2016-03-09 21:37 - 2016-03-09 21:37 - 00192216 _____ (Malwarebytes) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2016-03-09 21:35 - 2016-03-09 21:35 - 00001104 _____ C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2016-03-09 21:35 - 2016-03-09 21:35 - 00000000 ____D C:\ProgramData\Malwarebytes
2016-03-09 21:35 - 2016-03-09 21:35 - 00000000 ____D C:\Program Files (x86)\Malwarebytes Anti-Malware
2016-03-09 21:35 - 2015-10-05 09:50 - 00109272 _____ (Malwarebytes) C:\Windows\system32\Drivers\mbamchameleon.sys
2016-03-09 21:35 - 2015-10-05 09:50 - 00064216 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys
2016-03-09 21:35 - 2015-10-05 09:50 - 00025816 _____ (Malwarebytes) C:\Windows\system32\Drivers\mbam.sys
2016-03-09 21:34 - 2016-03-09 21:34 - 22908888 _____ (Malwarebytes ) C:\Users\Jakubko\Downloads\mbam-setup-2.2.0.1024.exe
2016-03-09 20:42 - 2016-03-09 21:30 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Anvisoft
2016-03-09 20:42 - 2016-03-09 20:42 - 00000000 ____D C:\ProgramData\boost_interprocess
2016-03-09 20:41 - 2015-09-17 02:52 - 00051608 _____ (Anvisoft) C:\Windows\system32\Drivers\asd2fsm.sys
2016-03-09 20:40 - 2016-03-09 20:40 - 00000000 ____D C:\ProgramData\Anvisoft
2016-03-09 20:40 - 2016-03-09 20:40 - 00000000 ____D C:\Program Files (x86)\Anvisoft
2016-03-09 20:39 - 2016-03-09 20:40 - 39269240 _____ (Anvisoft) C:\Users\Jakubko\Downloads\asdsetup.exe
2016-03-09 16:48 - 2016-03-09 16:48 - 00000000 ____D C:\Users\Jakubko\AppData\Roaming\Lavasoft
2016-03-09 16:36 - 2016-03-09 16:36 - 00000000 ____D C:\Users\Jakubko\AppData\Roaming\LavasoftStatistics
2016-03-09 16:35 - 2015-01-06 12:47 - 01061776 _____ (BitDefender S.R.L.) C:\Windows\system32\bdsmtpp.dll
2016-03-09 16:35 - 2015-01-06 12:47 - 00209984 _____ (BitDefender) C:\Windows\system32\BdFirewallSDK.dll
2016-03-09 16:35 - 2015-01-06 12:47 - 00195016 _____ (BitDefender) C:\Windows\system32\httproxy.dll
2016-03-09 16:35 - 2015-01-06 12:47 - 00156936 _____ C:\Windows\system32\bdfwcore.dll
2016-03-09 16:35 - 2015-01-06 12:47 - 00155912 _____ (BitDefender S.R.L.) C:\Windows\system32\bdpop3p.dll
2016-03-09 16:35 - 2015-01-06 12:47 - 00122928 _____ (BitDefender) C:\Windows\system32\OEMbdpredir.dll
2016-03-09 16:35 - 2015-01-06 12:47 - 00096160 _____ (BitDefender) C:\Windows\system32\bdpredir.dll
2016-03-09 16:33 - 2016-03-09 16:33 - 00000017 _____ C:\ProgramData\adaware-installer-reboot-required.tmp
2016-03-09 16:33 - 2016-03-09 16:33 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Lavasoft
2016-03-09 16:32 - 2016-03-09 16:32 - 00000000 ____H C:\Windows\system32\Drivers\Msft_Kernel_avchv_01009.Wdf
2016-03-09 16:32 - 2016-03-09 16:32 - 00000000 ____D C:\Windows\LastGood
2016-03-09 16:31 - 2016-03-09 16:31 - 00000000 ____D C:\Program Files\Lavasoft
2016-03-09 16:30 - 2016-03-09 16:30 - 00000000 ____D C:\Program Files\Common Files\Lavasoft
2016-03-09 16:29 - 2016-03-09 16:29 - 08493144 _____ C:\Users\Jakubko\Downloads\Adaware_Installer.exe
2016-03-09 16:29 - 2016-03-09 16:29 - 00000000 ____D C:\ProgramData\Lavasoft
2016-03-08 15:41 - 2016-03-08 15:42 - 44178450 _____ C:\Users\Jakubko\Downloads\MsZ 25.02.2016 #1 (online-video-cutter.com).mp4
2016-03-08 15:24 - 2016-03-09 17:40 - 00000000 ____D C:\ProgramData\Freemake
2016-03-08 15:24 - 2016-03-08 15:26 - 00000000 ____D C:\Users\Jakubko\Documents\Freemake
2016-03-08 15:24 - 2016-03-08 15:24 - 00001322 _____ C:\Users\Public\Desktop\Video Cutter.lnk
2016-03-08 15:22 - 2016-03-08 15:22 - 30968352 _____ (Ellora Assets Corporation ) C:\Users\Jakubko\Downloads\FreemakeVideoConverterFull.exe
2016-03-07 21:43 - 2016-03-07 21:43 - 00015102 _____ C:\Users\Jakubko\Downloads\int organisatons 15_16 evaluation.xlsx
2016-03-07 15:32 - 2016-03-07 15:33 - 41573347 _____ C:\Users\Jakubko\Downloads\Benefičný koncert venovaný spomienke Miňa Kočana.mp4
2016-03-07 15:24 - 2016-03-07 15:24 - 00000000 ____D C:\Users\Jakubko\AppData\LocalLow\uTorrent
2016-03-07 14:23 - 2016-03-07 14:23 - 00049244 _____ C:\Users\Jakubko\Desktop\Príkaz.PDF
2016-03-07 14:22 - 2016-03-07 14:22 - 00115495 _____ C:\Users\Jakubko\Desktop\Prihláška.pdf
2016-03-07 14:18 - 2016-03-07 14:18 - 00115495 _____ C:\Users\Jakubko\Downloads\gabor201457356745073.pdf
2016-03-07 14:18 - 2016-03-07 14:18 - 00049244 _____ C:\Users\Jakubko\Downloads\1457356747736.PDF
2016-03-07 11:39 - 2016-03-07 11:39 - 00005161 _____ C:\Users\Jakubko\Downloads\[kat.cr]the.walking.dead.s06e12.hdtv.x264.killers.ettv.torrent
2016-03-06 15:53 - 2016-03-06 15:53 - 00179538 _____ C:\Users\Jakubko\Downloads\Účasť poslancov msz na zasadnutiach - rok 2016 (1).pdf
2016-03-06 15:49 - 2016-03-06 15:49 - 00179538 _____ C:\Users\Jakubko\Downloads\Účasť poslancov msz na zasadnutiach - rok 2016.pdf
2016-03-06 15:48 - 2016-03-06 15:48 - 00288010 _____ C:\Users\Jakubko\Downloads\uznesenia msz 25. 02. 2016 - 156 - 185 - informácia.pdf
2016-03-06 13:25 - 2016-03-06 13:25 - 00000111 _____ C:\Users\Jakubko\Downloads\data-sdwsq.csv
2016-03-05 16:13 - 2016-03-05 16:13 - 00101552 _____ C:\Users\Jakubko\Downloads\MP-1501.pdf
2016-03-05 16:13 - 2016-03-05 16:13 - 00089832 _____ C:\Users\Jakubko\Downloads\KP-2015.pdf
2016-03-05 16:12 - 2016-03-05 16:12 - 00344608 _____ C:\Users\Jakubko\Downloads\RP-2015.xml
2016-03-05 16:12 - 2016-03-05 16:12 - 00025022 _____ C:\Users\Jakubko\Downloads\RP-2015.csv.zip
2016-03-05 16:11 - 2016-03-05 16:11 - 00104984 _____ C:\Users\Jakubko\Downloads\MP-1503.pdf
2016-03-05 16:10 - 2016-03-05 16:10 - 00000000 ____D C:\Users\Free.Jakub\AppData\Local\Adobe
2016-03-05 16:09 - 2016-03-05 16:11 - 00000000 ____D C:\Users\Free.Jakub\AppData\Roaming\Adobe
2016-03-05 16:09 - 2016-03-05 16:09 - 00002269 _____ C:\Users\Free.Jakub\Desktop\Google Chrome.lnk
2016-03-05 16:09 - 2016-03-05 16:09 - 00001432 _____ C:\Users\Free.Jakub\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
2016-03-05 16:09 - 2016-03-05 16:09 - 00000000 ____D C:\Users\Free.Jakub\AppData\Local\Google
2016-03-05 16:07 - 2016-03-05 16:09 - 00000000 ____D C:\Users\Free.Jakub\AppData\Local\Packages
2016-03-05 16:07 - 2016-03-05 16:07 - 00000000 ____D C:\Users\Free.Jakub\AppData\Local\VirtualStore
2016-03-05 16:06 - 2016-03-05 16:10 - 00000000 ____D C:\Users\Free.Jakub
2016-03-05 16:06 - 2016-03-05 16:06 - 00000020 ___SH C:\Users\Free.Jakub\ntuser.ini
2016-03-05 16:06 - 2013-11-05 12:27 - 00002207 _____ C:\Users\Free.Jakub\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\SkyDrive.lnk
2016-03-05 16:06 - 2013-10-25 15:47 - 00000000 ____D C:\Users\Free.Jakub\AppData\Local\Microsoft Help
2016-03-05 16:06 - 2013-09-17 08:45 - 00000000 ____D C:\Users\Free.Jakub\AppData\Roaming\Macromedia
2016-03-05 16:06 - 2013-09-16 13:12 - 00000000 ____D C:\Users\Free.Jakub\AppData\Roaming\ASUS WebStorage
2016-03-04 21:29 - 2016-03-04 21:29 - 09452149 _____ C:\Users\Jakubko\Downloads\Dcéram nedvíhal telefón...mp4
2016-03-04 21:27 - 2016-03-04 21:27 - 21445868 _____ C:\Users\Jakubko\Downloads\Záchrana zraneného zubra a auto-nehoda (1).mp4
2016-03-04 12:39 - 2016-03-04 12:39 - 00491312 _____ C:\Users\Jakubko\Downloads\Pozvanka_ck_OLP_XVIII_draft_8.pdf
2016-03-02 13:39 - 2016-03-02 13:39 - 00162481 _____ C:\Users\Jakubko\Desktop\VN SV-BA.pdf
2016-03-02 13:32 - 2016-03-02 13:32 - 00289928 _____ C:\Users\Jakubko\Desktop\VN BA-SV.pdf
2016-02-27 12:23 - 2016-03-09 18:48 - 00000000 ____D C:\Users\Jakubko\Desktop\Holokaust
2016-02-26 15:19 - 2016-03-06 19:50 - 00000000 ____D C:\Users\Jakubko\Desktop\KOMP
2016-02-15 21:26 - 2016-02-15 21:26 - 00000292 _____ C:\Users\Jakubko\Desktop\Pizzovníky.txt
2016-02-08 14:05 - 2016-02-15 13:57 - 00000000 ____D C:\Users\Jakubko\Desktop\Thermal
==================== One Month Modified files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2016-12-01 10:16 - 2013-09-16 13:12 - 00045056 _____ C:\Windows\SysWOW64\acovcnt.exe
2016-12-01 09:48 - 2014-08-26 14:18 - 00003490 _____ C:\Windows\System32\Tasks\AutoKMS
2016-03-09 21:54 - 2013-09-16 16:40 - 00000000 ____D C:\Users\Jakubko\AppData\Roaming\uTorrent
2016-03-09 21:32 - 2014-03-23 14:40 - 00000000 ____D C:\Users\Jakubko\AppData\Roaming\.ACEStream
2016-03-09 21:31 - 2013-10-23 17:05 - 00000000 ___HD C:\_acestream_cache_
2016-03-09 21:25 - 2014-07-12 14:20 - 00000948 _____ C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-303898890-2447975317-2344255173-1001UA.job
2016-03-09 21:07 - 2016-01-14 13:43 - 00000956 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2016-03-09 20:41 - 2012-07-26 06:37 - 00000000 ____D C:\Windows\Inf
2016-03-09 17:34 - 2016-01-14 11:22 - 00000000 ____D C:\Users\Jakubko\AppData\LocalLow\Adblock Plus for IE
2016-03-09 15:25 - 2014-07-12 14:20 - 00000926 _____ C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-303898890-2447975317-2344255173-1001Core.job
2016-03-09 09:29 - 2015-12-03 19:02 - 00107784 _____ C:\Users\Jakubko\Desktop\Dresy.xlsx
2016-03-09 09:07 - 2016-01-14 13:43 - 00000952 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2016-03-09 08:37 - 2013-09-16 10:36 - 00000000 ____D C:\Users\Jakubko\AppData\Local\Packages
2016-03-09 07:37 - 2012-08-15 17:46 - 00000739 _____ C:\Windows\SysWOW64\bscs.ini
2016-03-09 07:37 - 2012-07-26 09:12 - 00000000 ____D C:\Windows\AUInstallAgent
2016-03-09 07:36 - 2012-07-26 09:12 - 00000000 ___HD C:\Program Files\WindowsApps
2016-03-09 07:34 - 2013-03-31 09:44 - 00004268 _____ C:\Windows\SysWOW64\LOCALSERVICE.INI
2016-03-09 07:34 - 2013-03-31 09:44 - 00000043 _____ C:\Windows\SysWOW64\LOCALDEVICE.INI
2016-03-08 19:37 - 2014-06-02 20:25 - 00000000 ____D C:\Users\Jakubko\AppData\Roaming\vlc
2016-03-08 16:26 - 2016-01-15 13:58 - 00000000 ____D C:\Users\Jakubko\AppData\Roaming\Sony
2016-03-08 16:26 - 2016-01-14 19:53 - 00000000 ____D C:\Users\Jakubko\AppData\Roaming\TeamViewer
2016-03-08 16:26 - 2015-12-19 17:23 - 00000000 ____D C:\Users\Jakubko\AppData\Local\LogMeIn Hamachi
2016-03-08 16:26 - 2013-10-10 11:23 - 00000000 ____D C:\Users\Jakubko\AppData\Roaming\DAEMON Tools Lite
2016-03-08 16:09 - 2013-09-16 15:59 - 09584640 ___SH C:\Users\Jakubko\Desktop\Thumbs.db
2016-03-08 15:42 - 2013-10-13 14:38 - 06023680 ___SH C:\Users\Jakubko\Downloads\Thumbs.db
2016-03-08 15:14 - 2014-06-30 10:17 - 00004877 _____ C:\Users\Jakubko\Desktop\Neviem.txt
2016-03-08 14:38 - 2015-12-19 17:44 - 00000000 ____D C:\Program Files (x86)\EA Sports
2016-03-08 13:04 - 2013-09-17 10:46 - 00000132 _____ C:\Users\Jakubko\AppData\Roaming\Adobe PNG Format CS5 Prefs
2016-03-08 07:23 - 2013-10-29 09:22 - 00000427 _____ C:\Windows\SysWOW64\REMOTEDEVICE.INI
2016-03-07 11:42 - 2015-10-13 08:02 - 00000000 ____D C:\Users\Jakubko\Desktop\Download
2016-03-07 11:13 - 2013-03-31 09:47 - 00003056 _____ C:\Windows\System32\Tasks\ASUS P4G
2016-03-07 11:13 - 2013-03-31 09:47 - 00003028 _____ C:\Windows\System32\Tasks\ASUS USB Charger Plus
2016-03-07 11:12 - 2013-09-16 15:36 - 00000408 _____ C:\Users\Jakubko\AppData\Roaming\sp_data.sys
2016-03-06 16:04 - 2015-09-22 08:34 - 00290796 _____ C:\Users\Jakubko\Desktop\HLAS.psd
2016-03-05 16:21 - 2013-09-16 13:17 - 00003598 _____ C:\Windows\System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-303898890-2447975317-2344255173-1001
2016-03-05 16:10 - 2013-09-16 10:38 - 00000000 ____D C:\Windows\System32\Tasks\WPD
2016-03-04 17:02 - 2015-11-24 15:53 - 00000000 ____D C:\Users\Jakubko\Desktop\BC
2016-03-04 13:00 - 2015-03-18 20:13 - 00000000 ____D C:\Users\Jakubko\Desktop\Bazoš
2016-03-01 12:00 - 2012-07-26 08:28 - 00848230 _____ C:\Windows\system32\PerfStringBackup.INI
2016-02-26 21:07 - 2015-10-03 10:47 - 00000000 ____D C:\Users\Jakubko\Desktop\BORDEL
2016-02-20 07:10 - 2016-01-14 13:44 - 00002226 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2016-02-18 10:53 - 2014-12-05 17:04 - 00000000 ____D C:\Users\Jakubko\Desktop\3. ročník
2016-02-16 14:27 - 2016-01-14 19:51 - 00000000 ____D C:\Program Files (x86)\TeamViewer
2016-02-15 16:44 - 2016-01-25 08:45 - 00000000 ____D C:\Users\Jakubko\Desktop\TO
2016-02-15 12:08 - 2016-01-12 15:51 - 00000000 ____D C:\Users\Jakubko\Desktop\List
2016-02-14 12:17 - 2014-10-16 16:33 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java
2016-02-14 12:17 - 2014-10-16 16:33 - 00000000 ____D C:\Program Files (x86)\Java
2016-02-14 12:17 - 2013-09-26 09:36 - 00000000 ____D C:\ProgramData\Oracle
2016-02-14 12:16 - 2015-08-28 17:26 - 00000000 ____D C:\Users\Jakubko\.oracle_jre_usage
2016-02-14 12:14 - 2014-10-16 16:33 - 00097888 _____ (Oracle Corporation) C:\Windows\SysWOW64\WindowsAccessBridge-32.dll
2016-02-14 12:05 - 2014-01-03 23:59 - 05061280 _____ C:\Windows\system32\FNTCACHE.DAT
2016-02-14 12:05 - 2012-07-26 08:22 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2016-02-14 12:04 - 2012-07-26 06:26 - 00524288 ___SH C:\Windows\system32\config\BBI
2016-02-14 12:02 - 2012-07-26 09:12 - 00000000 ____D C:\Windows\system32\NDF
==================== Files in the root of some directories =======
2013-11-11 20:43 - 2014-07-20 13:08 - 0000132 _____ () C:\Users\Jakubko\AppData\Roaming\Adobe GIF Format CS5 Prefs
2013-09-17 10:46 - 2016-03-08 13:04 - 0000132 _____ () C:\Users\Jakubko\AppData\Roaming\Adobe PNG Format CS5 Prefs
2014-04-25 14:22 - 2014-04-25 15:05 - 0000000 _____ () C:\Users\Jakubko\AppData\Roaming\FileIn.cns
2014-04-25 14:22 - 2014-04-25 15:05 - 0000000 _____ () C:\Users\Jakubko\AppData\Roaming\FileOut.cns
2013-09-16 15:36 - 2016-03-07 11:12 - 0000408 _____ () C:\Users\Jakubko\AppData\Roaming\sp_data.sys
2013-11-12 11:44 - 2016-01-15 16:42 - 0001456 _____ () C:\Users\Jakubko\AppData\Local\Adobe Save for Web 12.0 Prefs
2014-10-31 19:48 - 2014-10-31 19:48 - 0007605 _____ () C:\Users\Jakubko\AppData\Local\Resmon.ResmonCfg
2016-03-09 16:33 - 2016-03-09 16:33 - 0000017 _____ () C:\ProgramData\adaware-installer-reboot-required.tmp
2012-11-23 14:06 - 2012-09-07 12:40 - 0000256 _____ () C:\ProgramData\SetStretch.cmd
2012-11-23 14:06 - 2009-07-22 11:04 - 0024576 _____ () C:\ProgramData\SetStretch.exe
2012-11-23 14:06 - 2012-09-07 12:37 - 0000103 _____ () C:\ProgramData\SetStretch.VBS
==================== Bamital & volsnap =================
(There is no automatic fix for files that do not pass verification.)
C:\Windows\system32\winlogon.exe => File is digitally signed
C:\Windows\system32\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\system32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\system32\services.exe => File is digitally signed
C:\Windows\system32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\system32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\system32\rpcss.dll => File is digitally signed
C:\Windows\system32\dnsapi.dll => File is digitally signed
C:\Windows\SysWOW64\dnsapi.dll => File is digitally signed
C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed
LastRegBack: 2016-03-07 15:12
==================== End of FRST.txt ============================