
Odvirování PC, zrychlení počítače, vzdálená pomoc prostřednictvím služby neslape.cz
Zasekany notebook
Moderátor: Moderátoři
Pravidla fóra
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]
Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.
!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]
Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.
!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Zasekany notebook
Dobry den prosim o kontrolu logu. Notebook se chova v posledni dobe divne, obcas zadrhava, mam herni notebook a hry ktere driv jeli v pohode nyni zadrhavaji nebo bezi s nizkymi fps. Diky.
Logfile of random's system information tool 1.10 (written by random/random)
Run by Blaze at 2016-03-30 22:29:10
Microsoft Windows 8.1
System drive C: has 451 GB (50%) free of 905 GB
Total RAM: 8139 MB (50% free)
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 22:29:14, on 30. 3. 2016
Platform: Unknown Windows (WinNT 6.02.1008)
MSIE: Internet Explorer v11.0 (11.00.9600.17416)
Boot mode: Normal
Running processes:
C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe
C:\Program Files (x86)\Razer\Synapse\RzSynapse.exe
C:\Program Files (x86)\Lenovo\YouCam\YCMMirage.exe
C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
C:\Program Files (x86)\Steam\Steam.exe
C:\Program Files (x86)\Steam\bin\steamwebhelper.exe
C:\Program Files (x86)\Steam\bin\steamwebhelper.exe
C:\Program Files (x86)\Steam\bin\steamwebhelper.exe
C:\Program Files (x86)\Origin\Origin.exe
C:\Program Files (x86)\Mozilla Firefox\firefox.exe
C:\Users\Blaze\AppData\Local\NVIDIA\NvBackend\ApplicationOntology\NvOAWrapperCache.exe
C:\Program Files\trend micro\Blaze.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://lenovo13.msn.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://lenovo13.msn.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/p/?LinkId=255141
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/p/?LinkId=255141
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F2 - REG:system.ini: UserInit=userinit.exe
O1 - Hosts: ˙ţ127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O4 - HKLM\..\Run: [IAStorIcon] C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIconLaunch.exe "C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe" 60
O4 - HKLM\..\Run: [Dolby Home Theater v4] "C:\Program Files (x86)\Dolby Home Theater v4\pcee4.exe" -autostart
O4 - HKLM\..\Run: [YouCam Mirage] "C:\Program Files (x86)\Lenovo\YouCam\YCMMirage.exe"
O4 - HKLM\..\Run: [YouCam Tray] "C:\Program Files (x86)\Lenovo\YouCam\YouCamTray.exe" /s
O4 - HKLM\..\Run: [Razer Synapse] "C:\Program Files (x86)\Razer\Synapse\RzSynapse.exe"
O4 - HKLM\..\Run: [LogMeIn Hamachi Ui] "C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe" --auto-start
O4 - HKCU\..\Run: [Steam] "C:\Program Files (x86)\Steam\steam.exe" -silent
O8 - Extra context menu item: Odeslat do Bluetooth - C:\Program Files (x86)\Intel\Bluetooth\btSendToObject.htm
O9 - Extra button: Odeslat do Bluetooth - {2F56DCAA-153B-4479-B4E2-547405B34FB9} - C:\Program Files (x86)\Intel\Bluetooth\btSendToPage.htm (HKCU)
O9 - Extra 'Tools' menuitem: Odeslat do Bluetooth - {2F56DCAA-153B-4479-B4E2-547405B34FB9} - C:\Program Files (x86)\Intel\Bluetooth\btSendToPage.htm (HKCU)
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\WINDOWS\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\WINDOWS\System32\alg.exe (file missing)
O23 - Service: Intel® Centrino® Wireless Bluetooth® + High Speed Service (AMPPALR3) - Intel Corporation - C:\Program Files\Intel\BluetoothHS\BTHSAmpPalService.exe
O23 - Service: BattlEye Service (BEService) - Unknown owner - C:\Program Files (x86)\Common Files\BattlEye\BEService.exe
O23 - Service: Bluetooth Device Monitor - Motorola Solutions, Inc. - C:\Program Files (x86)\Intel\Bluetooth\devmonsrv.exe
O23 - Service: Bluetooth OBEX Service - Motorola Solutions, Inc. - C:\Program Files (x86)\Intel\Bluetooth\obexsrv.exe
O23 - Service: Intel(R) Centrino(R) Wireless Bluetooth(R) + High Speed Security Service (BTHSSecurityMgr) - Intel(R) Corporation - C:\Program Files\Intel\BluetoothHS\BTHSSecurityMgr.exe
O23 - Service: EasyAntiCheat - EasyAntiCheat Ltd - C:\WINDOWS\system32\EasyAntiCheat.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\WINDOWS\System32\lsass.exe (file missing)
O23 - Service: Intel(R) PROSet/Wireless Event Log (EvtEng) - Intel(R) Corporation - C:\Program Files\Intel\WiFi\bin\EvtEng.exe
O23 - Service: ExpressCache - Diskeeper Corporation - C:\Program Files\Diskeeper Corporation\ExpressCache\ExpressCache.exe
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\WINDOWS\system32\fxssvc.exe (file missing)
O23 - Service: NVIDIA GeForce Experience Service (GfExperienceService) - NVIDIA Corporation - C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe
O23 - Service: LogMeIn Hamachi Tunneling Engine (Hamachi2Svc) - LogMeIn Inc. - C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2.exe
O23 - Service: Intel(R) Rapid Storage Technology (IAStorDataMgrSvc) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
O23 - Service: @%SystemRoot%\system32\ieetwcollectorres.dll,-1000 (IEEtwCollectorService) - Unknown owner - C:\WINDOWS\system32\IEEtwCollector.exe (file missing)
O23 - Service: Intel(R) Capability Licensing Service Interface - Intel(R) Corporation - C:\Program Files\Intel\iCLS Client\HeciServer.exe
O23 - Service: Intel(R) Dynamic Application Loader Host Interface Service (jhi_service) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: LMIGuardianSvc - LogMeIn, Inc. - C:\Program Files (x86)\LogMeIn Hamachi\LMIGuardianSvc.exe
O23 - Service: Intel(R) Management and Security Application Local Management Service (LMS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
O23 - Service: MBAMService - Malwarebytes Corporation - C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\WINDOWS\System32\msdtc.exe (file missing)
O23 - Service: Wireless PAN DHCP Server (MyWiFiDHCPDNS) - Unknown owner - C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: NVIDIA Network Service (NvNetworkService) - NVIDIA Corporation - C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe
O23 - Service: NVIDIA Streamer Network Service (NvStreamNetworkSvc) - NVIDIA Corporation - C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamNetworkService.exe
O23 - Service: NVIDIA Streamer Service (NvStreamSvc) - NVIDIA Corporation - C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamService.exe
O23 - Service: NVIDIA Display Driver Service (nvsvc) - Unknown owner - C:\WINDOWS\system32\nvvsvc.exe (file missing)
O23 - Service: Origin Client Service - Electronic Arts - C:\Program Files (x86)\Origin\OriginClientService.exe
O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe
O23 - Service: PnkBstrB - Unknown owner - C:\WINDOWS\system32\PnkBstrB.exe
O23 - Service: Razer Game Scanner (Razer Game Scanner Service) - Unknown owner - C:\Program Files (x86)\Razer\Razer Services\GSS\GameScannerService.exe
O23 - Service: Intel(R) PROSet/Wireless Registry Service (RegSrvc) - Intel(R) Corporation - C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\WINDOWS\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files (x86)\Skype\Updater\Updater.exe
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\WINDOWS\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\WINDOWS\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\WINDOWS\system32\sppsvc.exe (file missing)
O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files (x86)\Common Files\Steam\SteamService.exe
O23 - Service: NVIDIA Stereoscopic 3D Driver Service (Stereo Service) - NVIDIA Corporation - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\WINDOWS\system32\UI0Detect.exe (file missing)
O23 - Service: Intel(R) Management and Security Application User Notification Service (UNS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\WINDOWS\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\WINDOWS\system32\vssvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\WINDOWS\system32\wbengine.exe (file missing)
O23 - Service: @%ProgramFiles%\Windows Defender\MpAsDesc.dll,-320 (WdNisSvc) - Unknown owner - C:\Program Files (x86)\Windows Defender\NisSrv.exe (file missing)
O23 - Service: @%ProgramFiles%\Windows Defender\MpAsDesc.dll,-310 (WinDefend) - Unknown owner - C:\Program Files (x86)\Windows Defender\MsMpEng.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\WINDOWS\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)
O23 - Service: Intel(R) PROSet/Wireless Zero Configuration Service (ZeroConfigService) - Intel® Corporation - C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe
--
End of file - 10843 bytes
======Listing Processes======
wininit.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe -k DcomLaunch
C:\WINDOWS\system32\svchost.exe -k RPCSS
C:\WINDOWS\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\WINDOWS\system32\svchost.exe -k netsvcs
C:\WINDOWS\system32\svchost.exe -k LocalService
C:\WINDOWS\System32\svchost.exe -k LocalSystemNetworkRestricted
"C:\Windows\System32\WUDFHost.exe" -HostGUID:{193a1820-d9ac-4997-8c55-be817523f6aa} -IoEventPortName:HostProcess-9dbc7770-dd0c-47a1-89d7-00398f48e3e3 -SystemEventPortName:HostProcess-dbf51c07-5ce0-4081-b742-22822f496d2d -IoCancelEventPortName:HostProcess-705a1146-ca4b-4c35-8275-bffcd618e9c8 -NonStateChangingEventPortName:HostProcess-76b9637e-d29c-4001-8462-6e1e52a4234f -ServiceSID:S-1-5-80-2652678385-582572993-1835434367-1344795993-749280709 -LifetimeId:daabcb8a-f688-42b7-84bd-53f2fa9c010f -DeviceGroupId:WudfDefaultDevicePool
C:\WINDOWS\system32\svchost.exe -k NetworkService
C:\WINDOWS\System32\spoolsv.exe
C:\WINDOWS\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\WINDOWS\system32\svchost.exe -k LocalServiceNoNetwork
C:\WINDOWS\System32\svchost.exe -k utcsvc
"C:\Program Files\Intel\WiFi\bin\EvtEng.exe"
"C:\Program Files\Diskeeper Corporation\ExpressCache\ExpressCache.exe"
"C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe"
"C:\Program Files\Intel\iCLS Client\HeciServer.exe"
"C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe"
"C:\Program Files (x86)\LogMeIn Hamachi\LMIGuardianSvc.exe"
"C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe"
"C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamService.exe"
"C:\Program Files (x86)\Razer\Razer Services\GSS\GameScannerService.exe"
"C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe"
"C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe"
"C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamNetworkService.exe"
C:\WINDOWS\system32\SearchIndexer.exe /Embedding
"C:\Program Files (x86)\Intel\Bluetooth\devmonsrv.exe"
"C:\Program Files (x86)\Intel\Bluetooth\obexsrv.exe"
C:\WINDOWS\system32\wbem\unsecapp.exe -Embedding
C:\WINDOWS\system32\wbem\wmiprvse.exe
"C:\Program Files\Intel\BluetoothHS\BTHSAmpPalService.exe"
"C:\Program Files\Intel\BluetoothHS\BTHSSecurityMgr.exe"
"C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe"
"C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe"
"C:\WINDOWS\system32\nvvsvc.exe"
"C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe"
C:\WINDOWS\system32\PnkBstrA.exe
C:\WINDOWS\System32\WinLogon.exe -SpecialSession
-hiberboot
"C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe"
C:\WINDOWS\system32\nvvsvc.exe -session
C:\WINDOWS\system32\WLANExt.exe 797055088352
\??\C:\WINDOWS\system32\conhost.exe 0x4
"\Program Files\Synaptics\SynTP\SynTPEnh.exe"
taskhostex.exe
C:\WINDOWS\Explorer.EXE
"C:/Program Files/NVIDIA Corporation/Display/nvtray.exe" -user_has_logged_in 1"
"C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe"
"C:\PROGRAM FILES\SYNAPTICS\SYNTP\SYNTPHELPER.EXE"
"C:\Windows\RTFTrack.exe"
"C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe" -s
"C:\Program Files\Realtek\Audio\HDA\FMAPP.exe"
"C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe" /FORPCEE4
"C:\Program Files\Synaptics\SynTP\SynLenovoGestureMgr.exe" /m
"C:\Windows\System32\rundll32.exe" "C:\Program Files (x86)\Intel\Bluetooth\btmshell.dll",TrayApp
"C:\Program Files\Lenovo\Onekey Theater\OnekeyStudio.exe"
"C:\Program Files (x86)\Lenovo\Energy Management\Energy Management.exe"
"C:\Program Files (x86)\Lenovo\Energy Management\utility.exe"
"C:\Program Files (x86)\Dolby Home Theater v4\pcee4.exe" -autostart
"C:\Program Files (x86)\Razer\Synapse\RzSynapse.exe"
"C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamUserAgent.exe" serviceapp
\??\C:\WINDOWS\system32\conhost.exe 0x4
"C:\Program Files (x86)\Lenovo\YouCam\YCMMirage.exe"
"C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe"
"C:\Program Files (x86)\Steam\Steam.exe" "-silent"
"C:\Program Files (x86)\Steam\bin\steamwebhelper.exe" -cachedir="C:\Users\Blaze\AppData\Local\Steam\htmlcache" -steampid=55612 -buildid=1459198004 -steamid="0" --disable-gpu-compositing --disable-gpu --process-per-tab --enable-system-flash --disable-spell-checking --enable-widevine-cdm --enable-direct-write
"C:\Program Files (x86)\Common Files\Steam\SteamService.exe" /RunAsService
"C:\Program Files (x86)\Steam\bin\steamwebhelper.exe" --type=renderer --disable-gpu-compositing --enable-pinch --lang=en-US --lang=en-US --log-file="C:\Program Files (x86)\Steam\bin\debug.log" --product-version="Valve Steam Client" --disable-spell-checking --enable-system-flash --enable-pinch --device-scale-factor=1 --num-raster-threads=4 --content-image-texture-target=3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553 --video-image-texture-target=3553 --disable-gpu-compositing --channel="55624.1.1898352379\706287254" --font-cache-shared-handle=1456 /prefetch:673131151
"C:\WINDOWS\system32\wuauclt.exe"
"C:\Program Files (x86)\Steam\bin\steamwebhelper.exe" --type=renderer --disable-gpu-compositing --enable-pinch --lang=en-US --lang=en-US --log-file="C:\Program Files (x86)\Steam\bin\debug.log" --product-version="Valve Steam Client" --disable-spell-checking --enable-system-flash --enable-pinch --device-scale-factor=1 --num-raster-threads=4 --content-image-texture-target=3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553 --video-image-texture-target=3553 --disable-gpu-compositing --channel="55624.2.84176164\235826100" --font-cache-shared-handle=1280 /prefetch:673131151
"C:\Program Files\TeamSpeak 3 Client\ts3client_win64.exe"
taskhost.exe
"C:\Program Files (x86)\Origin\Origin.exe"
"C:\Program Files (x86)\Mozilla Firefox\firefox.exe" -osint -url "https://battlelog.battlefield.com/bf4/s ... iginclient"
"C:\Users\Blaze\AppData\Local\NVIDIA\NvBackend\ApplicationOntology\NvOAWrapperCache.exe"
C:\WINDOWS\SysWOW64\PnkBstrB.exe
C:\WINDOWS\system32\wbem\WmiApSrv.exe
"C:\Users\Blaze\Downloads\RSITx64.exe"
C:\WINDOWS\system32\wbem\wmiprvse.exe
======Scheduled tasks folder======
C:\WINDOWS\tasks\Adobe Flash Player Updater.job - C:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
C:\WINDOWS\tasks\Synaptics TouchPad Enhancements.job - C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
=========Mozilla firefox=========
ProfilePath - C:\Users\Blaze\AppData\Roaming\Mozilla\Firefox\Profiles\cwl9atgv.default-1428576093703
prefs.js - "browser.startup.homepage" - "https://seznam.cz/"
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 21.0.0.197 Plugin
"Path"=C:\WINDOWS\SysWOW64\Macromed\Flash\NPSWF32_21_0_0_197.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@esn/npbattlelog,version=2.7.1]
"Description"=
"Path"=C:\Program Files (x86)\Battlelog Web Plugins\2.7.1\npbattlelog.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@intel-webapi.intel.com/Intel WebAPI ipt;version=2.1.42]
"Description"=Intel IPT WebApi plugin
"Path"=C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@intel-webapi.intel.com/Intel WebAPI updater]
"Description"=This plugin updates Intel WebAPI component
"Path"=C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@nvidia.com/3DVision]
"Description"=NVIDIA stereo images plugin for Mozilla browsers
"Path"=C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@nvidia.com/3DVisionStreaming]
"Description"=NVIDIA 3D Vision Streaming plugin for Mozilla browsers
"Path"=C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@raidcall.en/RCplugin]
"Description"=Raidcall plugin
"Path"=C:\Users\Blaze\AppData\Roaming\raidcall\plugins\nprcplugin.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 21.0.0.197 Plugin
"Path"=C:\WINDOWS\system32\Macromed\Flash\NPSWF64_21_0_0_197.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@esn/npbattlelog,version=2.7.1]
"Description"=
"Path"=C:\Program Files (x86)\Battlelog Web Plugins\2.7.1\npbattlelogx64.dll
C:\Users\Blaze\AppData\Roaming\Mozilla\Firefox\Profiles\cwl9atgv.default-1428576093703\extensions\
artur.dubovoy@gmail.com
======Registry dump======
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"RtsFT"=C:\windows\RTFTrack.exe [2012-08-06 6334096]
"RtHDVCpl"=C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [2012-07-27 12937872]
"RtHDVBg_Dolby"=C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [2012-07-10 1214608]
"SynLenovoGestureMgr"=C:\Program Files\Synaptics\SynTP\SynLenovoGestureMgr.exe [2012-08-16 665400]
"BTMTrayAgent"=C:\Program Files (x86)\Intel\Bluetooth\btmshell.dll [2012-08-09 11554688]
"OnekeyStudio"=C:\Program Files\Lenovo\Onekey Theater\OnekeyStudio.exe [2012-08-10 4196432]
"Energy Management"=C:\Program Files (x86)\Lenovo\Energy Management\Energy Management.exe [2015-01-23 17080376]
"EnergyUtility"=C:\Program Files (x86)\Lenovo\Energy Management\Utility.exe [2015-01-23 191544]
"NvBackend"=C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe [2016-02-17 2789248]
"ShadowPlay"=C:\WINDOWS\system32\nvspcap64.dll [2016-02-17 1903344]
"SynTPEnh"=C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2012-08-16 2916152]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"Steam"=C:\Program Files (x86)\Steam\steam.exe [2016-03-28 3077712]
[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run]
"IAStorIcon"=C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIconLaunch.exe [2012-07-17 56128]
"Dolby Home Theater v4"=C:\Program Files (x86)\Dolby Home Theater v4\pcee4.exe [2012-07-26 508656]
"YouCam Mirage"=C:\Program Files (x86)\Lenovo\YouCam\YCMMirage.exe [2012-07-27 136488]
"YouCam Tray"=C:\Program Files (x86)\Lenovo\YouCam\YouCamTray.exe [2012-07-27 167024]
""= []
"Razer Synapse"=C:\Program Files (x86)\Razer\Synapse\RzSynapse.exe [2015-09-29 592704]
"LogMeIn Hamachi Ui"=C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe [2015-11-12 5565448]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"AppInit_DLLs"="C:\PROGRA~2\NVIDIA~1\3DVISI~1\NVSTIN~1.DLL"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Hamachi2Svc]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"VIDC.YUY2"=msyuv.dll
"vidc.i420"=iyuv_32.dll
"msacm.msgsm610"=msgsm32.acm
"msacm.msg711"=msg711.acm
"VIDC.YVYU"=msyuv.dll
"VIDC.YVU9"=tsbyuv.dll
"wavemapper"=msacm32.drv
"midimapper"=midimap.dll
"VIDC.UYVY"=msyuv.dll
"VIDC.IYUV"=iyuv_32.dll
"vidc.mrle"=msrle32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msadpcm"=msadp32.acm
"vidc.msvc"=msvidc32.dll
"MSVideo8"=VfWWDM32.dll
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
"wave2"=wdmaud.drv
"midi2"=wdmaud.drv
"mixer2"=wdmaud.drv
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
======File associations======
.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*
======List of files/folders created in the last 1 month======
2016-03-30 22:29:10 ----D---- C:\rsit
2016-03-25 18:28:36 ----A---- C:\WINDOWS\system32\PnkBstrA.exe
2016-03-23 16:50:00 ----A---- C:\WINDOWS\SYSWOW64\nvStreaming.exe
2016-03-23 16:49:54 ----A---- C:\WINDOWS\SYSWOW64\vulkaninfo.exe
2016-03-23 16:49:54 ----A---- C:\WINDOWS\SYSWOW64\vulkan-1.dll
2016-03-23 16:49:54 ----A---- C:\WINDOWS\system32\vulkaninfo.exe
2016-03-23 16:49:54 ----A---- C:\WINDOWS\system32\vulkan-1.dll
2016-03-23 16:49:32 ----D---- C:\Program Files (x86)\VulkanRT
2016-03-23 16:46:17 ----A---- C:\WINDOWS\SYSWOW64\nvwgf2um.dll
2016-03-23 16:46:17 ----A---- C:\WINDOWS\SYSWOW64\nvptxJitCompiler.dll
2016-03-23 16:46:17 ----A---- C:\WINDOWS\SYSWOW64\nvopencl.dll
2016-03-23 16:46:17 ----A---- C:\WINDOWS\SYSWOW64\nvoglv32.dll
2016-03-23 16:46:17 ----A---- C:\WINDOWS\SYSWOW64\NvIFROpenGL.dll
2016-03-23 16:46:17 ----A---- C:\WINDOWS\SYSWOW64\NvIFR.dll
2016-03-23 16:46:17 ----A---- C:\WINDOWS\SYSWOW64\NvFBC.dll
2016-03-23 16:46:17 ----A---- C:\WINDOWS\SYSWOW64\nvfatbinaryLoader.dll
2016-03-23 16:46:17 ----A---- C:\WINDOWS\SYSWOW64\nvEncodeAPI.dll
2016-03-23 16:46:17 ----A---- C:\WINDOWS\SYSWOW64\nvcuvid.dll
2016-03-23 16:46:17 ----A---- C:\WINDOWS\SYSWOW64\nvcuda.dll
2016-03-23 16:46:17 ----A---- C:\WINDOWS\SYSWOW64\nvcompiler.dll
2016-03-23 16:46:17 ----A---- C:\WINDOWS\system32\nvptxJitCompiler.dll
2016-03-23 16:46:17 ----A---- C:\WINDOWS\system32\nvopencl.dll
2016-03-23 16:46:17 ----A---- C:\WINDOWS\system32\nvoglv64.dll
2016-03-23 16:46:17 ----A---- C:\WINDOWS\system32\NvIFROpenGL.dll
2016-03-23 16:46:17 ----A---- C:\WINDOWS\system32\NvIFR64.dll
2016-03-23 16:46:17 ----A---- C:\WINDOWS\system32\NvFBC64.dll
2016-03-23 16:46:17 ----A---- C:\WINDOWS\system32\nvfatbinaryLoader.dll
2016-03-23 16:46:17 ----A---- C:\WINDOWS\system32\nvEncodeAPI64.dll
2016-03-23 16:46:17 ----A---- C:\WINDOWS\system32\nvdispgenco6436451.dll
2016-03-23 16:46:17 ----A---- C:\WINDOWS\system32\nvdispco6436451.dll
2016-03-23 16:46:17 ----A---- C:\WINDOWS\system32\nvd3dumx.dll
2016-03-23 16:46:17 ----A---- C:\WINDOWS\system32\nvcuvid.dll
2016-03-23 16:46:17 ----A---- C:\WINDOWS\system32\nvcuda.dll
2016-03-23 16:46:17 ----A---- C:\WINDOWS\system32\nvcompiler.dll
2016-03-23 16:46:17 ----A---- C:\WINDOWS\system32\drivers\nvlddmkm.sys
2016-03-23 15:40:10 ----A---- C:\WINDOWS\SYSWOW64\ucrtbase.dll
2016-03-23 15:40:10 ----A---- C:\WINDOWS\SYSWOW64\api-ms-win-crt-utility-l1-1-0.dll
2016-03-23 15:40:10 ----A---- C:\WINDOWS\SYSWOW64\api-ms-win-crt-time-l1-1-0.dll
2016-03-23 15:40:10 ----A---- C:\WINDOWS\SYSWOW64\api-ms-win-crt-string-l1-1-0.dll
2016-03-23 15:40:10 ----A---- C:\WINDOWS\SYSWOW64\api-ms-win-crt-stdio-l1-1-0.dll
2016-03-23 15:40:10 ----A---- C:\WINDOWS\SYSWOW64\api-ms-win-crt-runtime-l1-1-0.dll
2016-03-23 15:40:10 ----A---- C:\WINDOWS\SYSWOW64\api-ms-win-crt-process-l1-1-0.dll
2016-03-23 15:40:10 ----A---- C:\WINDOWS\SYSWOW64\api-ms-win-crt-private-l1-1-0.dll
2016-03-23 15:40:10 ----A---- C:\WINDOWS\SYSWOW64\api-ms-win-crt-multibyte-l1-1-0.dll
2016-03-23 15:40:10 ----A---- C:\WINDOWS\SYSWOW64\api-ms-win-crt-math-l1-1-0.dll
2016-03-23 15:40:10 ----A---- C:\WINDOWS\SYSWOW64\api-ms-win-crt-locale-l1-1-0.dll
2016-03-23 15:40:10 ----A---- C:\WINDOWS\SYSWOW64\api-ms-win-crt-heap-l1-1-0.dll
2016-03-23 15:40:10 ----A---- C:\WINDOWS\SYSWOW64\api-ms-win-crt-filesystem-l1-1-0.dll
2016-03-23 15:40:10 ----A---- C:\WINDOWS\SYSWOW64\api-ms-win-crt-environment-l1-1-0.dll
2016-03-23 15:40:10 ----A---- C:\WINDOWS\SYSWOW64\api-ms-win-crt-convert-l1-1-0.dll
2016-03-23 15:40:10 ----A---- C:\WINDOWS\SYSWOW64\api-ms-win-crt-conio-l1-1-0.dll
2016-03-23 15:40:10 ----A---- C:\WINDOWS\system32\ucrtbase.dll
2016-03-23 15:40:10 ----A---- C:\WINDOWS\system32\api-ms-win-crt-utility-l1-1-0.dll
2016-03-23 15:40:10 ----A---- C:\WINDOWS\system32\api-ms-win-crt-time-l1-1-0.dll
2016-03-23 15:40:10 ----A---- C:\WINDOWS\system32\api-ms-win-crt-string-l1-1-0.dll
2016-03-23 15:40:10 ----A---- C:\WINDOWS\system32\api-ms-win-crt-stdio-l1-1-0.dll
2016-03-23 15:40:10 ----A---- C:\WINDOWS\system32\api-ms-win-crt-runtime-l1-1-0.dll
2016-03-23 15:40:10 ----A---- C:\WINDOWS\system32\api-ms-win-crt-process-l1-1-0.dll
2016-03-23 15:40:10 ----A---- C:\WINDOWS\system32\api-ms-win-crt-private-l1-1-0.dll
2016-03-23 15:40:10 ----A---- C:\WINDOWS\system32\api-ms-win-crt-multibyte-l1-1-0.dll
2016-03-23 15:40:10 ----A---- C:\WINDOWS\system32\api-ms-win-crt-math-l1-1-0.dll
2016-03-23 15:40:10 ----A---- C:\WINDOWS\system32\api-ms-win-crt-locale-l1-1-0.dll
2016-03-23 15:40:10 ----A---- C:\WINDOWS\system32\api-ms-win-crt-heap-l1-1-0.dll
2016-03-23 15:40:10 ----A---- C:\WINDOWS\system32\api-ms-win-crt-filesystem-l1-1-0.dll
2016-03-23 15:40:10 ----A---- C:\WINDOWS\system32\api-ms-win-crt-environment-l1-1-0.dll
2016-03-23 15:40:10 ----A---- C:\WINDOWS\system32\api-ms-win-crt-convert-l1-1-0.dll
2016-03-23 15:40:10 ----A---- C:\WINDOWS\system32\api-ms-win-crt-conio-l1-1-0.dll
2016-03-19 22:56:46 ----D---- C:\Program Files (x86)\Mozilla Firefox
2016-03-13 21:22:32 ----D---- C:\Program Files (x86)\Battlelog Web Plugins
2016-03-13 20:04:04 ----D---- C:\Program Files (x86)\Origin Games
2016-03-13 19:58:47 ----D---- C:\Program Files (x86)\Origin
2016-03-02 02:44:50 ----A---- C:\WINDOWS\system32\nvdispgenco6436200.dll
2016-03-02 02:44:50 ----A---- C:\WINDOWS\system32\nvdispco6436200.dll
======List of files/folders modified in the last 1 month======
2016-03-30 22:29:13 ----D---- C:\Program Files\trend micro
2016-03-30 22:24:37 ----D---- C:\WINDOWS\SysWOW64
2016-03-30 22:24:35 ----A---- C:\WINDOWS\SYSWOW64\PnkBstrB.exe
2016-03-30 22:19:21 ----D---- C:\Users\Blaze\AppData\Roaming\TS3Client
2016-03-30 22:02:00 ----D---- C:\WINDOWS\system32\sru
2016-03-30 21:53:37 ----D---- C:\ProgramData\Origin
2016-03-30 21:15:03 ----D---- C:\WINDOWS\Temp
2016-03-30 21:15:03 ----D---- C:\WINDOWS\Prefetch
2016-03-30 21:12:33 ----D---- C:\WINDOWS\Microsoft.NET
2016-03-30 20:29:59 ----D---- C:\Program Files (x86)\Steam
2016-03-30 18:18:32 ----D---- C:\WINDOWS\Inf
2016-03-29 05:43:01 ----D---- C:\Users\Blaze\AppData\Roaming\Skype
2016-03-29 05:09:12 ----D---- C:\Program Files (x86)\World of Warcraft
2016-03-29 05:06:27 ----D---- C:\Program Files (x86)\Battle.net
2016-03-29 00:41:49 ----D---- C:\KMPlayer
2016-03-26 19:06:27 ----D---- C:\Program Files (x86)\Rockstar Games
2016-03-26 19:06:04 ----D---- C:\Program Files\Rockstar Games
2016-03-25 21:44:19 ----D---- C:\WINDOWS\system32\config
2016-03-25 21:42:01 ----D---- C:\WINDOWS\WinSxS
2016-03-25 18:28:36 ----RD---- C:\WINDOWS\System32
2016-03-25 09:50:19 ----A---- C:\WINDOWS\SYSWOW64\PnkBstrA.exe
2016-03-25 09:50:16 ----D---- C:\ProgramData\Package Cache
2016-03-25 09:49:01 ----RSD---- C:\WINDOWS\assembly
2016-03-25 09:48:22 ----SHD---- C:\System Volume Information
2016-03-25 00:53:20 ----D---- C:\WINDOWS\system32\drivers
2016-03-23 21:01:23 ----D---- C:\Windows
2016-03-23 16:50:19 ----D---- C:\ProgramData\NVIDIA Corporation
2016-03-23 16:50:12 ----D---- C:\ProgramData\NVIDIA
2016-03-23 16:49:57 ----D---- C:\WINDOWS\system32\DriverStore
2016-03-23 16:49:32 ----RD---- C:\Program Files (x86)
2016-03-23 15:40:28 ----SHD---- C:\WINDOWS\Installer
2016-03-23 15:40:25 ----D---- C:\WINDOWS\CbsTemp
2016-03-23 15:39:54 ----D---- C:\WINDOWS\SoftwareDistribution
2016-03-23 05:38:12 ----A---- C:\WINDOWS\SYSWOW64\EasyAntiCheat.exe
2016-03-23 02:48:12 ----D---- C:\Program Files (x86)\A3Launcher
2016-03-20 16:36:03 ----A---- C:\WINDOWS\SYSWOW64\log.txt
2016-03-20 16:33:17 ----D---- C:\WINDOWS\system32\catroot2
2016-03-20 16:31:20 ----D---- C:\Program Files (x86)\Mozilla Maintenance Service
2016-03-13 22:50:13 ----HD---- C:\Program Files\WindowsApps
2016-03-13 22:50:13 ----D---- C:\WINDOWS\AppReadiness
2016-03-09 23:26:04 ----D---- C:\ProgramData\Skype
2016-03-08 12:07:02 ----A---- C:\WINDOWS\SYSWOW64\nvd3dum.dll
2016-03-08 12:07:02 ----A---- C:\WINDOWS\SYSWOW64\nvapi.dll
2016-03-08 12:07:02 ----A---- C:\WINDOWS\system32\nvwgf2umx.dll
2016-03-08 12:07:02 ----A---- C:\WINDOWS\system32\nvapi64.dll
2016-03-08 08:27:51 ----A---- C:\WINDOWS\system32\nvsvc64.dll
2016-03-08 08:27:50 ----A---- C:\WINDOWS\system32\nvcpl.dll
2016-03-08 08:27:49 ----A---- C:\WINDOWS\SYSWOW64\oemdspif.dll
2016-03-08 08:27:49 ----A---- C:\WINDOWS\system32\nvvsvc.exe
2016-03-08 08:27:49 ----A---- C:\WINDOWS\system32\nvsvcr.dll
2016-03-08 08:27:48 ----A---- C:\WINDOWS\system32\nvshext.dll
2016-03-08 08:27:48 ----A---- C:\WINDOWS\system32\nvmctray.dll
2016-03-08 08:27:48 ----A---- C:\WINDOWS\system32\nv3dappshextr.dll
2016-03-08 08:27:48 ----A---- C:\WINDOWS\system32\nv3dappshext.dll
2016-03-03 01:44:06 ----D---- C:\Users\Blaze\AppData\Roaming\Battle.net
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R0 excsd;ExpressCache Storage Filter Driver; C:\WINDOWS\system32\DRIVERS\excsd.sys [2012-03-30 95024]
R0 iaStorA;iaStorA; C:\WINDOWS\System32\drivers\iaStorA.sys [2012-07-09 645952]
R0 LHDmgr;LHDmgr; C:\WINDOWS\System32\DRIVERS\LhdX64.sys [2015-01-23 39008]
R1 excfs;ExpressCache File System Filter Driver; C:\WINDOWS\system32\DRIVERS\excfs.sys [2012-03-30 23344]
R1 vwififlt;@%SystemRoot%\System32\drivers\vwififlt.sys,-259; C:\WINDOWS\system32\DRIVERS\vwififlt.sys [2013-08-22 71680]
R2 rzpmgrk;rzpmgrk; \??\C:\WINDOWS\system32\drivers\rzpmgrk.sys [2015-06-12 37184]
R2 rzpnk;rzpnk; \??\C:\WINDOWS\system32\drivers\rzpnk.sys [2015-06-27 129472]
R2 speedfan;speedfan; \??\C:\windows\SysWOW64\speedfan.sys [2012-12-29 28664]
R3 ACPIVPC;@oem43.inf,%ACPIVPC.SvcDesc%;Lenovo Virtual Power Controller Driver; C:\WINDOWS\System32\drivers\AcpiVpc.sys [2015-01-23 33560]
R3 AMPPAL;@oem47.inf,%AMPPAL.SVCDESC%;Virtuální adaptér Intel(r) Centrino(r) Wireless Bluetooth(r) + High Speed; C:\WINDOWS\System32\drivers\AMPPAL.sys [2013-05-21 165344]
R3 BthEnum;@bth.inf,%BthEnum.SVCDESC%;Služba Bluetooth Enumerator; C:\WINDOWS\system32\DRIVERS\BthEnum.sys [2014-11-21 53248]
R3 BthLEEnum;@bthleenum.inf,%BthLEEnum.SVCDESC%;Ovladač úspory energie technologie Bluetooth; C:\WINDOWS\system32\DRIVERS\BthLEEnum.sys [2014-11-21 226304]
R3 BthPan;@bthpan.inf,%BthPan.DisplayName%;Zařízení Bluetooth (síť PAN); C:\WINDOWS\system32\DRIVERS\bthpan.sys [2014-11-21 118272]
R3 BTHUSB;@bth.inf,%BTHUSB.SvcDesc%;Ovladač rozhraní USB radiostanice Bluetooth; C:\WINDOWS\System32\Drivers\BTHUSB.sys [2014-11-21 81920]
R3 btmhsf;btmhsf; C:\WINDOWS\system32\DRIVERS\btmhsf.sys [2012-07-15 825344]
R3 Hamachi;LogMeIn Hamachi Virtual Miniport); C:\WINDOWS\system32\DRIVERS\Hamdrv.sys [2015-11-12 45680]
R3 iBtFltCoex;iBtFltCoex; C:\WINDOWS\system32\DRIVERS\iBtFltCoex.sys [2012-07-04 55848]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\WINDOWS\system32\drivers\RTKVHD64.sys [2012-08-01 4103056]
R3 JMCR;JMCR; C:\WINDOWS\System32\drivers\jmcr.sys [2012-06-22 174176]
R3 L1C;@netl1c63x64.inf,%L1C.Service.DispName%;NDIS Miniport – ovladač pro řadič Qualcomm Atheros AR81xx PCI-E Ethernet; C:\WINDOWS\system32\DRIVERS\L1C63x64.sys [2013-06-18 129224]
R3 MBAMProtector;MBAMProtector; \??\C:\WINDOWS\system32\drivers\mbam.sys [2015-06-18 25816]
R3 MEIx64;@oem2.inf,%HECI_SvcDesc%;Intel(R) Management Engine Interface ; C:\WINDOWS\System32\drivers\HECIx64.sys [2012-07-03 62784]
R3 NETwNe64;@oem45.inf,%NIC_Service_DispName_WIN8_64%;Ovladač adaptéru řady Intel(R) Wireless WiFi Link 5000 pro systém Windows 8 64 Bit; C:\WINDOWS\system32\DRIVERS\Netwew00.sys [2013-10-08 3345376]
R3 NVHDA;@oem66.inf,%NVHDA.SvcDesc%;Service for NVIDIA High Definition Audio Driver; C:\WINDOWS\system32\drivers\nvhda64v.sys [2015-11-16 205456]
R3 nvlddmkm;nvlddmkm; C:\WINDOWS\system32\DRIVERS\nvlddmkm.sys [2016-03-08 12564024]
R3 NvStreamKms;NvStreamKms; \??\C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys [2016-02-17 28032]
R3 nvvad_WaveExtensible;@oem91.inf,%nvvad_WaveExtensible.SvcDesc%;NVIDIA Virtual Audio Device (Wave Extensible) (WDM); C:\WINDOWS\system32\drivers\nvvad64v.sys [2015-12-18 47760]
R3 RFCOMM;@tdibth.inf,%RFCOMM.DisplayName%;Zařízení Bluetooth (RFCOMM protokol TDI); C:\WINDOWS\system32\DRIVERS\rfcomm.sys [2015-04-16 167424]
R3 rtsuvc;@oem23.inf,%rtsuvc.DeviceDesc%;Lenovo EasyCamera; C:\WINDOWS\system32\DRIVERS\rtsuvc.sys [2012-08-06 8226832]
R3 rzudd;@oem86.inf,%Razer.SvcDesc%;Razer Mouse Driver; C:\WINDOWS\System32\drivers\rzudd.sys [2015-08-13 201432]
R3 SmbDrvI;SmbDrvI; C:\WINDOWS\system32\DRIVERS\Smb_driver_Intel.sys [2012-08-16 43832]
R3 SynTP;@oem6.inf,%SynTP.SvcDesc%;Synaptics TouchPad Driver; C:\WINDOWS\system32\DRIVERS\SynTP.sys [2012-08-16 447800]
S3 BTHPORT;@bth.inf,%BTHPORT.SvcDesc%;Ovladač portu Bluetooth; C:\WINDOWS\System32\Drivers\BTHport.sys [2014-11-21 1198080]
S3 MBAMSwissArmy;MBAMSwissArmy; \??\C:\WINDOWS\system32\drivers\MBAMSwissArmy.sys [2015-08-12 113880]
S3 MBAMWebAccessControl;MBAMWebAccessControl; \??\C:\WINDOWS\system32\drivers\mwac.sys [2015-06-18 64216]
S3 vwifimp;@%SystemRoot%\System32\drivers\vwifimp.sys,-261; C:\WINDOWS\system32\DRIVERS\vwifimp.sys [2013-08-22 36864]
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 AMPPALR3;Intel® Centrino® Wireless Bluetooth® + High Speed Service; C:\Program Files\Intel\BluetoothHS\BTHSAmpPalService.exe [2013-05-21 772064]
R2 Bluetooth Device Monitor;Bluetooth Device Monitor; C:\Program Files (x86)\Intel\Bluetooth\devmonsrv.exe [2012-08-08 1091520]
R2 Bluetooth OBEX Service;Bluetooth OBEX Service; C:\Program Files (x86)\Intel\Bluetooth\obexsrv.exe [2012-08-08 1112000]
R2 BTHSSecurityMgr;Intel(R) Centrino(R) Wireless Bluetooth(R) + High Speed Security Service; C:\Program Files\Intel\BluetoothHS\BTHSSecurityMgr.exe [2012-09-12 135984]
R2 DiagTrack;@%SystemRoot%\system32\diagtrack.dll,-3001; C:\WINDOWS\System32\svchost.exe [2014-11-21 38792]
R2 EvtEng;Intel(R) PROSet/Wireless Event Log; C:\Program Files\Intel\WiFi\bin\EvtEng.exe [2013-08-28 626416]
R2 ExpressCache;ExpressCache; C:\Program Files\Diskeeper Corporation\ExpressCache\ExpressCache.exe [2012-03-30 79664]
R2 GfExperienceService;NVIDIA GeForce Experience Service; C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe [2016-02-17 1164672]
R2 Intel(R) Capability Licensing Service Interface;Intel(R) Capability Licensing Service Interface; C:\Program Files\Intel\iCLS Client\HeciServer.exe [2012-04-21 635104]
R2 jhi_service;Intel(R) Dynamic Application Loader Host Interface Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [2012-06-25 166720]
R2 LMIGuardianSvc;LMIGuardianSvc; C:\Program Files (x86)\LogMeIn Hamachi\LMIGuardianSvc.exe [2015-11-12 417552]
R2 LMS;Intel(R) Management and Security Application Local Management Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe [2012-07-18 277824]
R2 NvNetworkService;NVIDIA Network Service; C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe [2016-02-17 1880960]
R2 NvStreamSvc;NVIDIA Streamer Service; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamService.exe [2016-02-17 2609024]
R2 nvsvc;NVIDIA Display Driver Service; C:\WINDOWS\system32\nvvsvc.exe [2016-03-08 1264064]
R2 PnkBstrA;PnkBstrA; C:\WINDOWS\system32\PnkBstrA.exe [2016-03-25 76152]
R2 PnkBstrB;PnkBstrB; C:\WINDOWS\syswow64\PnkBstrB.exe [2016-03-30 226168]
R2 Razer Game Scanner Service;Razer Game Scanner; C:\Program Files (x86)\Razer\Razer Services\GSS\GameScannerService.exe [2015-06-23 187048]
R2 RegSrvc;Intel(R) PROSet/Wireless Registry Service; C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe [2013-08-28 149744]
R2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service; C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [2016-03-08 424384]
R2 UNS;Intel(R) Management and Security Application User Notification Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe [2012-07-18 365376]
R3 NvStreamNetworkSvc;NVIDIA Streamer Network Service; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamNetworkService.exe [2016-02-17 6474112]
R3 Steam Client Service;Steam Client Service; C:\Program Files (x86)\Common Files\Steam\SteamService.exe [2016-03-28 835664]
S2 Hamachi2Svc;LogMeIn Hamachi Tunneling Engine; C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2.exe [2015-11-12 2546184]
S2 IAStorDataMgrSvc;Intel(R) Rapid Storage Technology; C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe [2012-07-09 7168]
S2 MBAMService;MBAMService; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe [2015-06-18 1133880]
S2 SkypeUpdate;Skype Updater; C:\Program Files (x86)\Skype\Updater\Updater.exe [2015-07-09 327296]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service; C:\WINDOWS\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2016-03-23 269504]
S3 BEService;BattlEye Service; C:\Program Files (x86)\Common Files\BattlEye\BEService.exe [2016-02-11 1345056]
S3 BthHFSrv;@%SystemRoot%\System32\BthHFSrv.dll,-103; C:\WINDOWS\System32\svchost.exe [2014-11-21 38792]
S3 EasyAntiCheat;EasyAntiCheat; C:\WINDOWS\syswow64\EasyAntiCheat.exe [2016-03-23 243984]
S3 FontCache3.0.0.0;@%SystemRoot%\system32\PresentationHost.exe,-3309; C:\WINDOWS\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe [2013-08-03 43696]
S3 MozillaMaintenance;Mozilla Maintenance Service; C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe [2016-03-19 146888]
S3 MyWiFiDHCPDNS;Wireless PAN DHCP Server; C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe [2013-08-28 273136]
S3 Origin Client Service;Origin Client Service; C:\Program Files (x86)\Origin\OriginClientService.exe [2016-03-30 2119688]
-----------------EOF-----------------
Logfile of random's system information tool 1.10 (written by random/random)
Run by Blaze at 2016-03-30 22:29:10
Microsoft Windows 8.1
System drive C: has 451 GB (50%) free of 905 GB
Total RAM: 8139 MB (50% free)
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 22:29:14, on 30. 3. 2016
Platform: Unknown Windows (WinNT 6.02.1008)
MSIE: Internet Explorer v11.0 (11.00.9600.17416)
Boot mode: Normal
Running processes:
C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe
C:\Program Files (x86)\Razer\Synapse\RzSynapse.exe
C:\Program Files (x86)\Lenovo\YouCam\YCMMirage.exe
C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
C:\Program Files (x86)\Steam\Steam.exe
C:\Program Files (x86)\Steam\bin\steamwebhelper.exe
C:\Program Files (x86)\Steam\bin\steamwebhelper.exe
C:\Program Files (x86)\Steam\bin\steamwebhelper.exe
C:\Program Files (x86)\Origin\Origin.exe
C:\Program Files (x86)\Mozilla Firefox\firefox.exe
C:\Users\Blaze\AppData\Local\NVIDIA\NvBackend\ApplicationOntology\NvOAWrapperCache.exe
C:\Program Files\trend micro\Blaze.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://lenovo13.msn.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://lenovo13.msn.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/p/?LinkId=255141
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/p/?LinkId=255141
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F2 - REG:system.ini: UserInit=userinit.exe
O1 - Hosts: ˙ţ127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O4 - HKLM\..\Run: [IAStorIcon] C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIconLaunch.exe "C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe" 60
O4 - HKLM\..\Run: [Dolby Home Theater v4] "C:\Program Files (x86)\Dolby Home Theater v4\pcee4.exe" -autostart
O4 - HKLM\..\Run: [YouCam Mirage] "C:\Program Files (x86)\Lenovo\YouCam\YCMMirage.exe"
O4 - HKLM\..\Run: [YouCam Tray] "C:\Program Files (x86)\Lenovo\YouCam\YouCamTray.exe" /s
O4 - HKLM\..\Run: [Razer Synapse] "C:\Program Files (x86)\Razer\Synapse\RzSynapse.exe"
O4 - HKLM\..\Run: [LogMeIn Hamachi Ui] "C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe" --auto-start
O4 - HKCU\..\Run: [Steam] "C:\Program Files (x86)\Steam\steam.exe" -silent
O8 - Extra context menu item: Odeslat do Bluetooth - C:\Program Files (x86)\Intel\Bluetooth\btSendToObject.htm
O9 - Extra button: Odeslat do Bluetooth - {2F56DCAA-153B-4479-B4E2-547405B34FB9} - C:\Program Files (x86)\Intel\Bluetooth\btSendToPage.htm (HKCU)
O9 - Extra 'Tools' menuitem: Odeslat do Bluetooth - {2F56DCAA-153B-4479-B4E2-547405B34FB9} - C:\Program Files (x86)\Intel\Bluetooth\btSendToPage.htm (HKCU)
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\WINDOWS\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\WINDOWS\System32\alg.exe (file missing)
O23 - Service: Intel® Centrino® Wireless Bluetooth® + High Speed Service (AMPPALR3) - Intel Corporation - C:\Program Files\Intel\BluetoothHS\BTHSAmpPalService.exe
O23 - Service: BattlEye Service (BEService) - Unknown owner - C:\Program Files (x86)\Common Files\BattlEye\BEService.exe
O23 - Service: Bluetooth Device Monitor - Motorola Solutions, Inc. - C:\Program Files (x86)\Intel\Bluetooth\devmonsrv.exe
O23 - Service: Bluetooth OBEX Service - Motorola Solutions, Inc. - C:\Program Files (x86)\Intel\Bluetooth\obexsrv.exe
O23 - Service: Intel(R) Centrino(R) Wireless Bluetooth(R) + High Speed Security Service (BTHSSecurityMgr) - Intel(R) Corporation - C:\Program Files\Intel\BluetoothHS\BTHSSecurityMgr.exe
O23 - Service: EasyAntiCheat - EasyAntiCheat Ltd - C:\WINDOWS\system32\EasyAntiCheat.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\WINDOWS\System32\lsass.exe (file missing)
O23 - Service: Intel(R) PROSet/Wireless Event Log (EvtEng) - Intel(R) Corporation - C:\Program Files\Intel\WiFi\bin\EvtEng.exe
O23 - Service: ExpressCache - Diskeeper Corporation - C:\Program Files\Diskeeper Corporation\ExpressCache\ExpressCache.exe
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\WINDOWS\system32\fxssvc.exe (file missing)
O23 - Service: NVIDIA GeForce Experience Service (GfExperienceService) - NVIDIA Corporation - C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe
O23 - Service: LogMeIn Hamachi Tunneling Engine (Hamachi2Svc) - LogMeIn Inc. - C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2.exe
O23 - Service: Intel(R) Rapid Storage Technology (IAStorDataMgrSvc) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
O23 - Service: @%SystemRoot%\system32\ieetwcollectorres.dll,-1000 (IEEtwCollectorService) - Unknown owner - C:\WINDOWS\system32\IEEtwCollector.exe (file missing)
O23 - Service: Intel(R) Capability Licensing Service Interface - Intel(R) Corporation - C:\Program Files\Intel\iCLS Client\HeciServer.exe
O23 - Service: Intel(R) Dynamic Application Loader Host Interface Service (jhi_service) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: LMIGuardianSvc - LogMeIn, Inc. - C:\Program Files (x86)\LogMeIn Hamachi\LMIGuardianSvc.exe
O23 - Service: Intel(R) Management and Security Application Local Management Service (LMS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
O23 - Service: MBAMService - Malwarebytes Corporation - C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\WINDOWS\System32\msdtc.exe (file missing)
O23 - Service: Wireless PAN DHCP Server (MyWiFiDHCPDNS) - Unknown owner - C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: NVIDIA Network Service (NvNetworkService) - NVIDIA Corporation - C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe
O23 - Service: NVIDIA Streamer Network Service (NvStreamNetworkSvc) - NVIDIA Corporation - C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamNetworkService.exe
O23 - Service: NVIDIA Streamer Service (NvStreamSvc) - NVIDIA Corporation - C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamService.exe
O23 - Service: NVIDIA Display Driver Service (nvsvc) - Unknown owner - C:\WINDOWS\system32\nvvsvc.exe (file missing)
O23 - Service: Origin Client Service - Electronic Arts - C:\Program Files (x86)\Origin\OriginClientService.exe
O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe
O23 - Service: PnkBstrB - Unknown owner - C:\WINDOWS\system32\PnkBstrB.exe
O23 - Service: Razer Game Scanner (Razer Game Scanner Service) - Unknown owner - C:\Program Files (x86)\Razer\Razer Services\GSS\GameScannerService.exe
O23 - Service: Intel(R) PROSet/Wireless Registry Service (RegSrvc) - Intel(R) Corporation - C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\WINDOWS\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files (x86)\Skype\Updater\Updater.exe
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\WINDOWS\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\WINDOWS\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\WINDOWS\system32\sppsvc.exe (file missing)
O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files (x86)\Common Files\Steam\SteamService.exe
O23 - Service: NVIDIA Stereoscopic 3D Driver Service (Stereo Service) - NVIDIA Corporation - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\WINDOWS\system32\UI0Detect.exe (file missing)
O23 - Service: Intel(R) Management and Security Application User Notification Service (UNS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\WINDOWS\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\WINDOWS\system32\vssvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\WINDOWS\system32\wbengine.exe (file missing)
O23 - Service: @%ProgramFiles%\Windows Defender\MpAsDesc.dll,-320 (WdNisSvc) - Unknown owner - C:\Program Files (x86)\Windows Defender\NisSrv.exe (file missing)
O23 - Service: @%ProgramFiles%\Windows Defender\MpAsDesc.dll,-310 (WinDefend) - Unknown owner - C:\Program Files (x86)\Windows Defender\MsMpEng.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\WINDOWS\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)
O23 - Service: Intel(R) PROSet/Wireless Zero Configuration Service (ZeroConfigService) - Intel® Corporation - C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe
--
End of file - 10843 bytes
======Listing Processes======
wininit.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe -k DcomLaunch
C:\WINDOWS\system32\svchost.exe -k RPCSS
C:\WINDOWS\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\WINDOWS\system32\svchost.exe -k netsvcs
C:\WINDOWS\system32\svchost.exe -k LocalService
C:\WINDOWS\System32\svchost.exe -k LocalSystemNetworkRestricted
"C:\Windows\System32\WUDFHost.exe" -HostGUID:{193a1820-d9ac-4997-8c55-be817523f6aa} -IoEventPortName:HostProcess-9dbc7770-dd0c-47a1-89d7-00398f48e3e3 -SystemEventPortName:HostProcess-dbf51c07-5ce0-4081-b742-22822f496d2d -IoCancelEventPortName:HostProcess-705a1146-ca4b-4c35-8275-bffcd618e9c8 -NonStateChangingEventPortName:HostProcess-76b9637e-d29c-4001-8462-6e1e52a4234f -ServiceSID:S-1-5-80-2652678385-582572993-1835434367-1344795993-749280709 -LifetimeId:daabcb8a-f688-42b7-84bd-53f2fa9c010f -DeviceGroupId:WudfDefaultDevicePool
C:\WINDOWS\system32\svchost.exe -k NetworkService
C:\WINDOWS\System32\spoolsv.exe
C:\WINDOWS\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\WINDOWS\system32\svchost.exe -k LocalServiceNoNetwork
C:\WINDOWS\System32\svchost.exe -k utcsvc
"C:\Program Files\Intel\WiFi\bin\EvtEng.exe"
"C:\Program Files\Diskeeper Corporation\ExpressCache\ExpressCache.exe"
"C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe"
"C:\Program Files\Intel\iCLS Client\HeciServer.exe"
"C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe"
"C:\Program Files (x86)\LogMeIn Hamachi\LMIGuardianSvc.exe"
"C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe"
"C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamService.exe"
"C:\Program Files (x86)\Razer\Razer Services\GSS\GameScannerService.exe"
"C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe"
"C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe"
"C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamNetworkService.exe"
C:\WINDOWS\system32\SearchIndexer.exe /Embedding
"C:\Program Files (x86)\Intel\Bluetooth\devmonsrv.exe"
"C:\Program Files (x86)\Intel\Bluetooth\obexsrv.exe"
C:\WINDOWS\system32\wbem\unsecapp.exe -Embedding
C:\WINDOWS\system32\wbem\wmiprvse.exe
"C:\Program Files\Intel\BluetoothHS\BTHSAmpPalService.exe"
"C:\Program Files\Intel\BluetoothHS\BTHSSecurityMgr.exe"
"C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe"
"C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe"
"C:\WINDOWS\system32\nvvsvc.exe"
"C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe"
C:\WINDOWS\system32\PnkBstrA.exe
C:\WINDOWS\System32\WinLogon.exe -SpecialSession
-hiberboot
"C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe"
C:\WINDOWS\system32\nvvsvc.exe -session
C:\WINDOWS\system32\WLANExt.exe 797055088352
\??\C:\WINDOWS\system32\conhost.exe 0x4
"\Program Files\Synaptics\SynTP\SynTPEnh.exe"
taskhostex.exe
C:\WINDOWS\Explorer.EXE
"C:/Program Files/NVIDIA Corporation/Display/nvtray.exe" -user_has_logged_in 1"
"C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe"
"C:\PROGRAM FILES\SYNAPTICS\SYNTP\SYNTPHELPER.EXE"
"C:\Windows\RTFTrack.exe"
"C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe" -s
"C:\Program Files\Realtek\Audio\HDA\FMAPP.exe"
"C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe" /FORPCEE4
"C:\Program Files\Synaptics\SynTP\SynLenovoGestureMgr.exe" /m
"C:\Windows\System32\rundll32.exe" "C:\Program Files (x86)\Intel\Bluetooth\btmshell.dll",TrayApp
"C:\Program Files\Lenovo\Onekey Theater\OnekeyStudio.exe"
"C:\Program Files (x86)\Lenovo\Energy Management\Energy Management.exe"
"C:\Program Files (x86)\Lenovo\Energy Management\utility.exe"
"C:\Program Files (x86)\Dolby Home Theater v4\pcee4.exe" -autostart
"C:\Program Files (x86)\Razer\Synapse\RzSynapse.exe"
"C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamUserAgent.exe" serviceapp
\??\C:\WINDOWS\system32\conhost.exe 0x4
"C:\Program Files (x86)\Lenovo\YouCam\YCMMirage.exe"
"C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe"
"C:\Program Files (x86)\Steam\Steam.exe" "-silent"
"C:\Program Files (x86)\Steam\bin\steamwebhelper.exe" -cachedir="C:\Users\Blaze\AppData\Local\Steam\htmlcache" -steampid=55612 -buildid=1459198004 -steamid="0" --disable-gpu-compositing --disable-gpu --process-per-tab --enable-system-flash --disable-spell-checking --enable-widevine-cdm --enable-direct-write
"C:\Program Files (x86)\Common Files\Steam\SteamService.exe" /RunAsService
"C:\Program Files (x86)\Steam\bin\steamwebhelper.exe" --type=renderer --disable-gpu-compositing --enable-pinch --lang=en-US --lang=en-US --log-file="C:\Program Files (x86)\Steam\bin\debug.log" --product-version="Valve Steam Client" --disable-spell-checking --enable-system-flash --enable-pinch --device-scale-factor=1 --num-raster-threads=4 --content-image-texture-target=3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553 --video-image-texture-target=3553 --disable-gpu-compositing --channel="55624.1.1898352379\706287254" --font-cache-shared-handle=1456 /prefetch:673131151
"C:\WINDOWS\system32\wuauclt.exe"
"C:\Program Files (x86)\Steam\bin\steamwebhelper.exe" --type=renderer --disable-gpu-compositing --enable-pinch --lang=en-US --lang=en-US --log-file="C:\Program Files (x86)\Steam\bin\debug.log" --product-version="Valve Steam Client" --disable-spell-checking --enable-system-flash --enable-pinch --device-scale-factor=1 --num-raster-threads=4 --content-image-texture-target=3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553 --video-image-texture-target=3553 --disable-gpu-compositing --channel="55624.2.84176164\235826100" --font-cache-shared-handle=1280 /prefetch:673131151
"C:\Program Files\TeamSpeak 3 Client\ts3client_win64.exe"
taskhost.exe
"C:\Program Files (x86)\Origin\Origin.exe"
"C:\Program Files (x86)\Mozilla Firefox\firefox.exe" -osint -url "https://battlelog.battlefield.com/bf4/s ... iginclient"
"C:\Users\Blaze\AppData\Local\NVIDIA\NvBackend\ApplicationOntology\NvOAWrapperCache.exe"
C:\WINDOWS\SysWOW64\PnkBstrB.exe
C:\WINDOWS\system32\wbem\WmiApSrv.exe
"C:\Users\Blaze\Downloads\RSITx64.exe"
C:\WINDOWS\system32\wbem\wmiprvse.exe
======Scheduled tasks folder======
C:\WINDOWS\tasks\Adobe Flash Player Updater.job - C:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
C:\WINDOWS\tasks\Synaptics TouchPad Enhancements.job - C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
=========Mozilla firefox=========
ProfilePath - C:\Users\Blaze\AppData\Roaming\Mozilla\Firefox\Profiles\cwl9atgv.default-1428576093703
prefs.js - "browser.startup.homepage" - "https://seznam.cz/"
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 21.0.0.197 Plugin
"Path"=C:\WINDOWS\SysWOW64\Macromed\Flash\NPSWF32_21_0_0_197.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@esn/npbattlelog,version=2.7.1]
"Description"=
"Path"=C:\Program Files (x86)\Battlelog Web Plugins\2.7.1\npbattlelog.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@intel-webapi.intel.com/Intel WebAPI ipt;version=2.1.42]
"Description"=Intel IPT WebApi plugin
"Path"=C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@intel-webapi.intel.com/Intel WebAPI updater]
"Description"=This plugin updates Intel WebAPI component
"Path"=C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@nvidia.com/3DVision]
"Description"=NVIDIA stereo images plugin for Mozilla browsers
"Path"=C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@nvidia.com/3DVisionStreaming]
"Description"=NVIDIA 3D Vision Streaming plugin for Mozilla browsers
"Path"=C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@raidcall.en/RCplugin]
"Description"=Raidcall plugin
"Path"=C:\Users\Blaze\AppData\Roaming\raidcall\plugins\nprcplugin.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 21.0.0.197 Plugin
"Path"=C:\WINDOWS\system32\Macromed\Flash\NPSWF64_21_0_0_197.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@esn/npbattlelog,version=2.7.1]
"Description"=
"Path"=C:\Program Files (x86)\Battlelog Web Plugins\2.7.1\npbattlelogx64.dll
C:\Users\Blaze\AppData\Roaming\Mozilla\Firefox\Profiles\cwl9atgv.default-1428576093703\extensions\
artur.dubovoy@gmail.com
======Registry dump======
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"RtsFT"=C:\windows\RTFTrack.exe [2012-08-06 6334096]
"RtHDVCpl"=C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [2012-07-27 12937872]
"RtHDVBg_Dolby"=C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [2012-07-10 1214608]
"SynLenovoGestureMgr"=C:\Program Files\Synaptics\SynTP\SynLenovoGestureMgr.exe [2012-08-16 665400]
"BTMTrayAgent"=C:\Program Files (x86)\Intel\Bluetooth\btmshell.dll [2012-08-09 11554688]
"OnekeyStudio"=C:\Program Files\Lenovo\Onekey Theater\OnekeyStudio.exe [2012-08-10 4196432]
"Energy Management"=C:\Program Files (x86)\Lenovo\Energy Management\Energy Management.exe [2015-01-23 17080376]
"EnergyUtility"=C:\Program Files (x86)\Lenovo\Energy Management\Utility.exe [2015-01-23 191544]
"NvBackend"=C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe [2016-02-17 2789248]
"ShadowPlay"=C:\WINDOWS\system32\nvspcap64.dll [2016-02-17 1903344]
"SynTPEnh"=C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2012-08-16 2916152]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"Steam"=C:\Program Files (x86)\Steam\steam.exe [2016-03-28 3077712]
[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run]
"IAStorIcon"=C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIconLaunch.exe [2012-07-17 56128]
"Dolby Home Theater v4"=C:\Program Files (x86)\Dolby Home Theater v4\pcee4.exe [2012-07-26 508656]
"YouCam Mirage"=C:\Program Files (x86)\Lenovo\YouCam\YCMMirage.exe [2012-07-27 136488]
"YouCam Tray"=C:\Program Files (x86)\Lenovo\YouCam\YouCamTray.exe [2012-07-27 167024]
""= []
"Razer Synapse"=C:\Program Files (x86)\Razer\Synapse\RzSynapse.exe [2015-09-29 592704]
"LogMeIn Hamachi Ui"=C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe [2015-11-12 5565448]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"AppInit_DLLs"="C:\PROGRA~2\NVIDIA~1\3DVISI~1\NVSTIN~1.DLL"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Hamachi2Svc]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"VIDC.YUY2"=msyuv.dll
"vidc.i420"=iyuv_32.dll
"msacm.msgsm610"=msgsm32.acm
"msacm.msg711"=msg711.acm
"VIDC.YVYU"=msyuv.dll
"VIDC.YVU9"=tsbyuv.dll
"wavemapper"=msacm32.drv
"midimapper"=midimap.dll
"VIDC.UYVY"=msyuv.dll
"VIDC.IYUV"=iyuv_32.dll
"vidc.mrle"=msrle32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msadpcm"=msadp32.acm
"vidc.msvc"=msvidc32.dll
"MSVideo8"=VfWWDM32.dll
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
"wave2"=wdmaud.drv
"midi2"=wdmaud.drv
"mixer2"=wdmaud.drv
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
======File associations======
.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*
======List of files/folders created in the last 1 month======
2016-03-30 22:29:10 ----D---- C:\rsit
2016-03-25 18:28:36 ----A---- C:\WINDOWS\system32\PnkBstrA.exe
2016-03-23 16:50:00 ----A---- C:\WINDOWS\SYSWOW64\nvStreaming.exe
2016-03-23 16:49:54 ----A---- C:\WINDOWS\SYSWOW64\vulkaninfo.exe
2016-03-23 16:49:54 ----A---- C:\WINDOWS\SYSWOW64\vulkan-1.dll
2016-03-23 16:49:54 ----A---- C:\WINDOWS\system32\vulkaninfo.exe
2016-03-23 16:49:54 ----A---- C:\WINDOWS\system32\vulkan-1.dll
2016-03-23 16:49:32 ----D---- C:\Program Files (x86)\VulkanRT
2016-03-23 16:46:17 ----A---- C:\WINDOWS\SYSWOW64\nvwgf2um.dll
2016-03-23 16:46:17 ----A---- C:\WINDOWS\SYSWOW64\nvptxJitCompiler.dll
2016-03-23 16:46:17 ----A---- C:\WINDOWS\SYSWOW64\nvopencl.dll
2016-03-23 16:46:17 ----A---- C:\WINDOWS\SYSWOW64\nvoglv32.dll
2016-03-23 16:46:17 ----A---- C:\WINDOWS\SYSWOW64\NvIFROpenGL.dll
2016-03-23 16:46:17 ----A---- C:\WINDOWS\SYSWOW64\NvIFR.dll
2016-03-23 16:46:17 ----A---- C:\WINDOWS\SYSWOW64\NvFBC.dll
2016-03-23 16:46:17 ----A---- C:\WINDOWS\SYSWOW64\nvfatbinaryLoader.dll
2016-03-23 16:46:17 ----A---- C:\WINDOWS\SYSWOW64\nvEncodeAPI.dll
2016-03-23 16:46:17 ----A---- C:\WINDOWS\SYSWOW64\nvcuvid.dll
2016-03-23 16:46:17 ----A---- C:\WINDOWS\SYSWOW64\nvcuda.dll
2016-03-23 16:46:17 ----A---- C:\WINDOWS\SYSWOW64\nvcompiler.dll
2016-03-23 16:46:17 ----A---- C:\WINDOWS\system32\nvptxJitCompiler.dll
2016-03-23 16:46:17 ----A---- C:\WINDOWS\system32\nvopencl.dll
2016-03-23 16:46:17 ----A---- C:\WINDOWS\system32\nvoglv64.dll
2016-03-23 16:46:17 ----A---- C:\WINDOWS\system32\NvIFROpenGL.dll
2016-03-23 16:46:17 ----A---- C:\WINDOWS\system32\NvIFR64.dll
2016-03-23 16:46:17 ----A---- C:\WINDOWS\system32\NvFBC64.dll
2016-03-23 16:46:17 ----A---- C:\WINDOWS\system32\nvfatbinaryLoader.dll
2016-03-23 16:46:17 ----A---- C:\WINDOWS\system32\nvEncodeAPI64.dll
2016-03-23 16:46:17 ----A---- C:\WINDOWS\system32\nvdispgenco6436451.dll
2016-03-23 16:46:17 ----A---- C:\WINDOWS\system32\nvdispco6436451.dll
2016-03-23 16:46:17 ----A---- C:\WINDOWS\system32\nvd3dumx.dll
2016-03-23 16:46:17 ----A---- C:\WINDOWS\system32\nvcuvid.dll
2016-03-23 16:46:17 ----A---- C:\WINDOWS\system32\nvcuda.dll
2016-03-23 16:46:17 ----A---- C:\WINDOWS\system32\nvcompiler.dll
2016-03-23 16:46:17 ----A---- C:\WINDOWS\system32\drivers\nvlddmkm.sys
2016-03-23 15:40:10 ----A---- C:\WINDOWS\SYSWOW64\ucrtbase.dll
2016-03-23 15:40:10 ----A---- C:\WINDOWS\SYSWOW64\api-ms-win-crt-utility-l1-1-0.dll
2016-03-23 15:40:10 ----A---- C:\WINDOWS\SYSWOW64\api-ms-win-crt-time-l1-1-0.dll
2016-03-23 15:40:10 ----A---- C:\WINDOWS\SYSWOW64\api-ms-win-crt-string-l1-1-0.dll
2016-03-23 15:40:10 ----A---- C:\WINDOWS\SYSWOW64\api-ms-win-crt-stdio-l1-1-0.dll
2016-03-23 15:40:10 ----A---- C:\WINDOWS\SYSWOW64\api-ms-win-crt-runtime-l1-1-0.dll
2016-03-23 15:40:10 ----A---- C:\WINDOWS\SYSWOW64\api-ms-win-crt-process-l1-1-0.dll
2016-03-23 15:40:10 ----A---- C:\WINDOWS\SYSWOW64\api-ms-win-crt-private-l1-1-0.dll
2016-03-23 15:40:10 ----A---- C:\WINDOWS\SYSWOW64\api-ms-win-crt-multibyte-l1-1-0.dll
2016-03-23 15:40:10 ----A---- C:\WINDOWS\SYSWOW64\api-ms-win-crt-math-l1-1-0.dll
2016-03-23 15:40:10 ----A---- C:\WINDOWS\SYSWOW64\api-ms-win-crt-locale-l1-1-0.dll
2016-03-23 15:40:10 ----A---- C:\WINDOWS\SYSWOW64\api-ms-win-crt-heap-l1-1-0.dll
2016-03-23 15:40:10 ----A---- C:\WINDOWS\SYSWOW64\api-ms-win-crt-filesystem-l1-1-0.dll
2016-03-23 15:40:10 ----A---- C:\WINDOWS\SYSWOW64\api-ms-win-crt-environment-l1-1-0.dll
2016-03-23 15:40:10 ----A---- C:\WINDOWS\SYSWOW64\api-ms-win-crt-convert-l1-1-0.dll
2016-03-23 15:40:10 ----A---- C:\WINDOWS\SYSWOW64\api-ms-win-crt-conio-l1-1-0.dll
2016-03-23 15:40:10 ----A---- C:\WINDOWS\system32\ucrtbase.dll
2016-03-23 15:40:10 ----A---- C:\WINDOWS\system32\api-ms-win-crt-utility-l1-1-0.dll
2016-03-23 15:40:10 ----A---- C:\WINDOWS\system32\api-ms-win-crt-time-l1-1-0.dll
2016-03-23 15:40:10 ----A---- C:\WINDOWS\system32\api-ms-win-crt-string-l1-1-0.dll
2016-03-23 15:40:10 ----A---- C:\WINDOWS\system32\api-ms-win-crt-stdio-l1-1-0.dll
2016-03-23 15:40:10 ----A---- C:\WINDOWS\system32\api-ms-win-crt-runtime-l1-1-0.dll
2016-03-23 15:40:10 ----A---- C:\WINDOWS\system32\api-ms-win-crt-process-l1-1-0.dll
2016-03-23 15:40:10 ----A---- C:\WINDOWS\system32\api-ms-win-crt-private-l1-1-0.dll
2016-03-23 15:40:10 ----A---- C:\WINDOWS\system32\api-ms-win-crt-multibyte-l1-1-0.dll
2016-03-23 15:40:10 ----A---- C:\WINDOWS\system32\api-ms-win-crt-math-l1-1-0.dll
2016-03-23 15:40:10 ----A---- C:\WINDOWS\system32\api-ms-win-crt-locale-l1-1-0.dll
2016-03-23 15:40:10 ----A---- C:\WINDOWS\system32\api-ms-win-crt-heap-l1-1-0.dll
2016-03-23 15:40:10 ----A---- C:\WINDOWS\system32\api-ms-win-crt-filesystem-l1-1-0.dll
2016-03-23 15:40:10 ----A---- C:\WINDOWS\system32\api-ms-win-crt-environment-l1-1-0.dll
2016-03-23 15:40:10 ----A---- C:\WINDOWS\system32\api-ms-win-crt-convert-l1-1-0.dll
2016-03-23 15:40:10 ----A---- C:\WINDOWS\system32\api-ms-win-crt-conio-l1-1-0.dll
2016-03-19 22:56:46 ----D---- C:\Program Files (x86)\Mozilla Firefox
2016-03-13 21:22:32 ----D---- C:\Program Files (x86)\Battlelog Web Plugins
2016-03-13 20:04:04 ----D---- C:\Program Files (x86)\Origin Games
2016-03-13 19:58:47 ----D---- C:\Program Files (x86)\Origin
2016-03-02 02:44:50 ----A---- C:\WINDOWS\system32\nvdispgenco6436200.dll
2016-03-02 02:44:50 ----A---- C:\WINDOWS\system32\nvdispco6436200.dll
======List of files/folders modified in the last 1 month======
2016-03-30 22:29:13 ----D---- C:\Program Files\trend micro
2016-03-30 22:24:37 ----D---- C:\WINDOWS\SysWOW64
2016-03-30 22:24:35 ----A---- C:\WINDOWS\SYSWOW64\PnkBstrB.exe
2016-03-30 22:19:21 ----D---- C:\Users\Blaze\AppData\Roaming\TS3Client
2016-03-30 22:02:00 ----D---- C:\WINDOWS\system32\sru
2016-03-30 21:53:37 ----D---- C:\ProgramData\Origin
2016-03-30 21:15:03 ----D---- C:\WINDOWS\Temp
2016-03-30 21:15:03 ----D---- C:\WINDOWS\Prefetch
2016-03-30 21:12:33 ----D---- C:\WINDOWS\Microsoft.NET
2016-03-30 20:29:59 ----D---- C:\Program Files (x86)\Steam
2016-03-30 18:18:32 ----D---- C:\WINDOWS\Inf
2016-03-29 05:43:01 ----D---- C:\Users\Blaze\AppData\Roaming\Skype
2016-03-29 05:09:12 ----D---- C:\Program Files (x86)\World of Warcraft
2016-03-29 05:06:27 ----D---- C:\Program Files (x86)\Battle.net
2016-03-29 00:41:49 ----D---- C:\KMPlayer
2016-03-26 19:06:27 ----D---- C:\Program Files (x86)\Rockstar Games
2016-03-26 19:06:04 ----D---- C:\Program Files\Rockstar Games
2016-03-25 21:44:19 ----D---- C:\WINDOWS\system32\config
2016-03-25 21:42:01 ----D---- C:\WINDOWS\WinSxS
2016-03-25 18:28:36 ----RD---- C:\WINDOWS\System32
2016-03-25 09:50:19 ----A---- C:\WINDOWS\SYSWOW64\PnkBstrA.exe
2016-03-25 09:50:16 ----D---- C:\ProgramData\Package Cache
2016-03-25 09:49:01 ----RSD---- C:\WINDOWS\assembly
2016-03-25 09:48:22 ----SHD---- C:\System Volume Information
2016-03-25 00:53:20 ----D---- C:\WINDOWS\system32\drivers
2016-03-23 21:01:23 ----D---- C:\Windows
2016-03-23 16:50:19 ----D---- C:\ProgramData\NVIDIA Corporation
2016-03-23 16:50:12 ----D---- C:\ProgramData\NVIDIA
2016-03-23 16:49:57 ----D---- C:\WINDOWS\system32\DriverStore
2016-03-23 16:49:32 ----RD---- C:\Program Files (x86)
2016-03-23 15:40:28 ----SHD---- C:\WINDOWS\Installer
2016-03-23 15:40:25 ----D---- C:\WINDOWS\CbsTemp
2016-03-23 15:39:54 ----D---- C:\WINDOWS\SoftwareDistribution
2016-03-23 05:38:12 ----A---- C:\WINDOWS\SYSWOW64\EasyAntiCheat.exe
2016-03-23 02:48:12 ----D---- C:\Program Files (x86)\A3Launcher
2016-03-20 16:36:03 ----A---- C:\WINDOWS\SYSWOW64\log.txt
2016-03-20 16:33:17 ----D---- C:\WINDOWS\system32\catroot2
2016-03-20 16:31:20 ----D---- C:\Program Files (x86)\Mozilla Maintenance Service
2016-03-13 22:50:13 ----HD---- C:\Program Files\WindowsApps
2016-03-13 22:50:13 ----D---- C:\WINDOWS\AppReadiness
2016-03-09 23:26:04 ----D---- C:\ProgramData\Skype
2016-03-08 12:07:02 ----A---- C:\WINDOWS\SYSWOW64\nvd3dum.dll
2016-03-08 12:07:02 ----A---- C:\WINDOWS\SYSWOW64\nvapi.dll
2016-03-08 12:07:02 ----A---- C:\WINDOWS\system32\nvwgf2umx.dll
2016-03-08 12:07:02 ----A---- C:\WINDOWS\system32\nvapi64.dll
2016-03-08 08:27:51 ----A---- C:\WINDOWS\system32\nvsvc64.dll
2016-03-08 08:27:50 ----A---- C:\WINDOWS\system32\nvcpl.dll
2016-03-08 08:27:49 ----A---- C:\WINDOWS\SYSWOW64\oemdspif.dll
2016-03-08 08:27:49 ----A---- C:\WINDOWS\system32\nvvsvc.exe
2016-03-08 08:27:49 ----A---- C:\WINDOWS\system32\nvsvcr.dll
2016-03-08 08:27:48 ----A---- C:\WINDOWS\system32\nvshext.dll
2016-03-08 08:27:48 ----A---- C:\WINDOWS\system32\nvmctray.dll
2016-03-08 08:27:48 ----A---- C:\WINDOWS\system32\nv3dappshextr.dll
2016-03-08 08:27:48 ----A---- C:\WINDOWS\system32\nv3dappshext.dll
2016-03-03 01:44:06 ----D---- C:\Users\Blaze\AppData\Roaming\Battle.net
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R0 excsd;ExpressCache Storage Filter Driver; C:\WINDOWS\system32\DRIVERS\excsd.sys [2012-03-30 95024]
R0 iaStorA;iaStorA; C:\WINDOWS\System32\drivers\iaStorA.sys [2012-07-09 645952]
R0 LHDmgr;LHDmgr; C:\WINDOWS\System32\DRIVERS\LhdX64.sys [2015-01-23 39008]
R1 excfs;ExpressCache File System Filter Driver; C:\WINDOWS\system32\DRIVERS\excfs.sys [2012-03-30 23344]
R1 vwififlt;@%SystemRoot%\System32\drivers\vwififlt.sys,-259; C:\WINDOWS\system32\DRIVERS\vwififlt.sys [2013-08-22 71680]
R2 rzpmgrk;rzpmgrk; \??\C:\WINDOWS\system32\drivers\rzpmgrk.sys [2015-06-12 37184]
R2 rzpnk;rzpnk; \??\C:\WINDOWS\system32\drivers\rzpnk.sys [2015-06-27 129472]
R2 speedfan;speedfan; \??\C:\windows\SysWOW64\speedfan.sys [2012-12-29 28664]
R3 ACPIVPC;@oem43.inf,%ACPIVPC.SvcDesc%;Lenovo Virtual Power Controller Driver; C:\WINDOWS\System32\drivers\AcpiVpc.sys [2015-01-23 33560]
R3 AMPPAL;@oem47.inf,%AMPPAL.SVCDESC%;Virtuální adaptér Intel(r) Centrino(r) Wireless Bluetooth(r) + High Speed; C:\WINDOWS\System32\drivers\AMPPAL.sys [2013-05-21 165344]
R3 BthEnum;@bth.inf,%BthEnum.SVCDESC%;Služba Bluetooth Enumerator; C:\WINDOWS\system32\DRIVERS\BthEnum.sys [2014-11-21 53248]
R3 BthLEEnum;@bthleenum.inf,%BthLEEnum.SVCDESC%;Ovladač úspory energie technologie Bluetooth; C:\WINDOWS\system32\DRIVERS\BthLEEnum.sys [2014-11-21 226304]
R3 BthPan;@bthpan.inf,%BthPan.DisplayName%;Zařízení Bluetooth (síť PAN); C:\WINDOWS\system32\DRIVERS\bthpan.sys [2014-11-21 118272]
R3 BTHUSB;@bth.inf,%BTHUSB.SvcDesc%;Ovladač rozhraní USB radiostanice Bluetooth; C:\WINDOWS\System32\Drivers\BTHUSB.sys [2014-11-21 81920]
R3 btmhsf;btmhsf; C:\WINDOWS\system32\DRIVERS\btmhsf.sys [2012-07-15 825344]
R3 Hamachi;LogMeIn Hamachi Virtual Miniport); C:\WINDOWS\system32\DRIVERS\Hamdrv.sys [2015-11-12 45680]
R3 iBtFltCoex;iBtFltCoex; C:\WINDOWS\system32\DRIVERS\iBtFltCoex.sys [2012-07-04 55848]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\WINDOWS\system32\drivers\RTKVHD64.sys [2012-08-01 4103056]
R3 JMCR;JMCR; C:\WINDOWS\System32\drivers\jmcr.sys [2012-06-22 174176]
R3 L1C;@netl1c63x64.inf,%L1C.Service.DispName%;NDIS Miniport – ovladač pro řadič Qualcomm Atheros AR81xx PCI-E Ethernet; C:\WINDOWS\system32\DRIVERS\L1C63x64.sys [2013-06-18 129224]
R3 MBAMProtector;MBAMProtector; \??\C:\WINDOWS\system32\drivers\mbam.sys [2015-06-18 25816]
R3 MEIx64;@oem2.inf,%HECI_SvcDesc%;Intel(R) Management Engine Interface ; C:\WINDOWS\System32\drivers\HECIx64.sys [2012-07-03 62784]
R3 NETwNe64;@oem45.inf,%NIC_Service_DispName_WIN8_64%;Ovladač adaptéru řady Intel(R) Wireless WiFi Link 5000 pro systém Windows 8 64 Bit; C:\WINDOWS\system32\DRIVERS\Netwew00.sys [2013-10-08 3345376]
R3 NVHDA;@oem66.inf,%NVHDA.SvcDesc%;Service for NVIDIA High Definition Audio Driver; C:\WINDOWS\system32\drivers\nvhda64v.sys [2015-11-16 205456]
R3 nvlddmkm;nvlddmkm; C:\WINDOWS\system32\DRIVERS\nvlddmkm.sys [2016-03-08 12564024]
R3 NvStreamKms;NvStreamKms; \??\C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys [2016-02-17 28032]
R3 nvvad_WaveExtensible;@oem91.inf,%nvvad_WaveExtensible.SvcDesc%;NVIDIA Virtual Audio Device (Wave Extensible) (WDM); C:\WINDOWS\system32\drivers\nvvad64v.sys [2015-12-18 47760]
R3 RFCOMM;@tdibth.inf,%RFCOMM.DisplayName%;Zařízení Bluetooth (RFCOMM protokol TDI); C:\WINDOWS\system32\DRIVERS\rfcomm.sys [2015-04-16 167424]
R3 rtsuvc;@oem23.inf,%rtsuvc.DeviceDesc%;Lenovo EasyCamera; C:\WINDOWS\system32\DRIVERS\rtsuvc.sys [2012-08-06 8226832]
R3 rzudd;@oem86.inf,%Razer.SvcDesc%;Razer Mouse Driver; C:\WINDOWS\System32\drivers\rzudd.sys [2015-08-13 201432]
R3 SmbDrvI;SmbDrvI; C:\WINDOWS\system32\DRIVERS\Smb_driver_Intel.sys [2012-08-16 43832]
R3 SynTP;@oem6.inf,%SynTP.SvcDesc%;Synaptics TouchPad Driver; C:\WINDOWS\system32\DRIVERS\SynTP.sys [2012-08-16 447800]
S3 BTHPORT;@bth.inf,%BTHPORT.SvcDesc%;Ovladač portu Bluetooth; C:\WINDOWS\System32\Drivers\BTHport.sys [2014-11-21 1198080]
S3 MBAMSwissArmy;MBAMSwissArmy; \??\C:\WINDOWS\system32\drivers\MBAMSwissArmy.sys [2015-08-12 113880]
S3 MBAMWebAccessControl;MBAMWebAccessControl; \??\C:\WINDOWS\system32\drivers\mwac.sys [2015-06-18 64216]
S3 vwifimp;@%SystemRoot%\System32\drivers\vwifimp.sys,-261; C:\WINDOWS\system32\DRIVERS\vwifimp.sys [2013-08-22 36864]
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 AMPPALR3;Intel® Centrino® Wireless Bluetooth® + High Speed Service; C:\Program Files\Intel\BluetoothHS\BTHSAmpPalService.exe [2013-05-21 772064]
R2 Bluetooth Device Monitor;Bluetooth Device Monitor; C:\Program Files (x86)\Intel\Bluetooth\devmonsrv.exe [2012-08-08 1091520]
R2 Bluetooth OBEX Service;Bluetooth OBEX Service; C:\Program Files (x86)\Intel\Bluetooth\obexsrv.exe [2012-08-08 1112000]
R2 BTHSSecurityMgr;Intel(R) Centrino(R) Wireless Bluetooth(R) + High Speed Security Service; C:\Program Files\Intel\BluetoothHS\BTHSSecurityMgr.exe [2012-09-12 135984]
R2 DiagTrack;@%SystemRoot%\system32\diagtrack.dll,-3001; C:\WINDOWS\System32\svchost.exe [2014-11-21 38792]
R2 EvtEng;Intel(R) PROSet/Wireless Event Log; C:\Program Files\Intel\WiFi\bin\EvtEng.exe [2013-08-28 626416]
R2 ExpressCache;ExpressCache; C:\Program Files\Diskeeper Corporation\ExpressCache\ExpressCache.exe [2012-03-30 79664]
R2 GfExperienceService;NVIDIA GeForce Experience Service; C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe [2016-02-17 1164672]
R2 Intel(R) Capability Licensing Service Interface;Intel(R) Capability Licensing Service Interface; C:\Program Files\Intel\iCLS Client\HeciServer.exe [2012-04-21 635104]
R2 jhi_service;Intel(R) Dynamic Application Loader Host Interface Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [2012-06-25 166720]
R2 LMIGuardianSvc;LMIGuardianSvc; C:\Program Files (x86)\LogMeIn Hamachi\LMIGuardianSvc.exe [2015-11-12 417552]
R2 LMS;Intel(R) Management and Security Application Local Management Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe [2012-07-18 277824]
R2 NvNetworkService;NVIDIA Network Service; C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe [2016-02-17 1880960]
R2 NvStreamSvc;NVIDIA Streamer Service; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamService.exe [2016-02-17 2609024]
R2 nvsvc;NVIDIA Display Driver Service; C:\WINDOWS\system32\nvvsvc.exe [2016-03-08 1264064]
R2 PnkBstrA;PnkBstrA; C:\WINDOWS\system32\PnkBstrA.exe [2016-03-25 76152]
R2 PnkBstrB;PnkBstrB; C:\WINDOWS\syswow64\PnkBstrB.exe [2016-03-30 226168]
R2 Razer Game Scanner Service;Razer Game Scanner; C:\Program Files (x86)\Razer\Razer Services\GSS\GameScannerService.exe [2015-06-23 187048]
R2 RegSrvc;Intel(R) PROSet/Wireless Registry Service; C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe [2013-08-28 149744]
R2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service; C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [2016-03-08 424384]
R2 UNS;Intel(R) Management and Security Application User Notification Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe [2012-07-18 365376]
R3 NvStreamNetworkSvc;NVIDIA Streamer Network Service; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamNetworkService.exe [2016-02-17 6474112]
R3 Steam Client Service;Steam Client Service; C:\Program Files (x86)\Common Files\Steam\SteamService.exe [2016-03-28 835664]
S2 Hamachi2Svc;LogMeIn Hamachi Tunneling Engine; C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2.exe [2015-11-12 2546184]
S2 IAStorDataMgrSvc;Intel(R) Rapid Storage Technology; C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe [2012-07-09 7168]
S2 MBAMService;MBAMService; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe [2015-06-18 1133880]
S2 SkypeUpdate;Skype Updater; C:\Program Files (x86)\Skype\Updater\Updater.exe [2015-07-09 327296]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service; C:\WINDOWS\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2016-03-23 269504]
S3 BEService;BattlEye Service; C:\Program Files (x86)\Common Files\BattlEye\BEService.exe [2016-02-11 1345056]
S3 BthHFSrv;@%SystemRoot%\System32\BthHFSrv.dll,-103; C:\WINDOWS\System32\svchost.exe [2014-11-21 38792]
S3 EasyAntiCheat;EasyAntiCheat; C:\WINDOWS\syswow64\EasyAntiCheat.exe [2016-03-23 243984]
S3 FontCache3.0.0.0;@%SystemRoot%\system32\PresentationHost.exe,-3309; C:\WINDOWS\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe [2013-08-03 43696]
S3 MozillaMaintenance;Mozilla Maintenance Service; C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe [2016-03-19 146888]
S3 MyWiFiDHCPDNS;Wireless PAN DHCP Server; C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe [2013-08-28 273136]
S3 Origin Client Service;Origin Client Service; C:\Program Files (x86)\Origin\OriginClientService.exe [2016-03-30 2119688]
-----------------EOF-----------------
Re: Zasekany notebook
Krasny den Vam preju 
V ramci cisteni Vam budou vyprazdneny docasne adresare (vcetne Kose).
Ulozte na plochu AdwCleaner https://toolslib.net/downloads/viewdown ... dwcleaner/ (nebo http://www.bleepingcomputer.com/download/adwcleaner/ )
- ukoncete vsechny programy
- kliknete pravym na ikonu AdwCleaneru a vyberte Spustit jako spravce (v pripade Win XP spustte obycejne dvojklikem)
- kliknete na Scan, pote na Cleaning
- po restartu na Vas vyskoci log (pripadne jej najdete v C:\AdwCleaner\AdwCleaner[Cx].txt), jehoz obsah zkopirujte do pristi odpovedi
Pokud je cokoliv nejasného, ihned se ptej.
V případě spokojenosti prosím podpořte forum.
Pro dotazy, které se nehodí na forum, je možné využít altrokzavináčforum.viry.cz
Máš-li chuť pomáhat návštěvníkům tohoto fora, přihlas se do naší školičky.
V případě spokojenosti prosím podpořte forum.
Pro dotazy, které se nehodí na forum, je možné využít altrokzavináčforum.viry.cz
Máš-li chuť pomáhat návštěvníkům tohoto fora, přihlas se do naší školičky.
Re: Zasekany notebook
***** [ Soubory ] *****
***** [ DLLs ] *****
***** [ Zástupci ] *****
***** [ Naplánované úkoly ] *****
***** [ Registr ] *****
[-] Klávesa smazáno : HKCU\Software\Mail.Ru
[-] Klávesa smazáno : HKCU\Software\AppDataLow\Software\Mail.Ru
***** [ Webové prohlížeče ] *****
*************************
:: "Tracing" odstraněných kláves
:: Nastavení Winsock odstraněno
*************************
C:\AdwCleaner\AdwCleaner[C1].txt - [856 bytes] - [31/03/2016 01:06:26]
C:\AdwCleaner\AdwCleaner[C7].txt - [734 bytes] - [07/01/2016 00:35:09]
C:\AdwCleaner\AdwCleaner[R0].txt - [740 bytes] - [06/06/2015 20:07:35]
C:\AdwCleaner\AdwCleaner[R1].txt - [852 bytes] - [08/07/2015 18:50:30]
C:\AdwCleaner\AdwCleaner[R2].txt - [966 bytes] - [22/07/2015 23:33:59]
C:\AdwCleaner\AdwCleaner[R3].txt - [1082 bytes] - [24/07/2015 21:12:10]
C:\AdwCleaner\AdwCleaner[R4].txt - [1203 bytes] - [11/08/2015 22:51:04]
C:\AdwCleaner\AdwCleaner[R5].txt - [1313 bytes] - [21/11/2015 16:50:18]
C:\AdwCleaner\AdwCleaner[S0].txt - [801 bytes] - [06/06/2015 20:08:37]
C:\AdwCleaner\AdwCleaner[S1].txt - [2921 bytes] - [08/07/2015 18:51:07]
C:\AdwCleaner\AdwCleaner[S2].txt - [1027 bytes] - [22/07/2015 23:34:38]
C:\AdwCleaner\AdwCleaner[S3].txt - [1145 bytes] - [24/07/2015 21:12:36]
C:\AdwCleaner\AdwCleaner[S4].txt - [1266 bytes] - [11/08/2015 22:52:18]
C:\AdwCleaner\AdwCleaner[S5].txt - [1376 bytes] - [21/11/2015 16:50:45]
C:\AdwCleaner\AdwCleaner[S7].txt - [642 bytes] - [07/01/2016 00:32:36]
########## EOF - C:\AdwCleaner\AdwCleaner[C1].txt - [1944 bytes] ##########
***** [ DLLs ] *****
***** [ Zástupci ] *****
***** [ Naplánované úkoly ] *****
***** [ Registr ] *****
[-] Klávesa smazáno : HKCU\Software\Mail.Ru
[-] Klávesa smazáno : HKCU\Software\AppDataLow\Software\Mail.Ru
***** [ Webové prohlížeče ] *****
*************************
:: "Tracing" odstraněných kláves
:: Nastavení Winsock odstraněno
*************************
C:\AdwCleaner\AdwCleaner[C1].txt - [856 bytes] - [31/03/2016 01:06:26]
C:\AdwCleaner\AdwCleaner[C7].txt - [734 bytes] - [07/01/2016 00:35:09]
C:\AdwCleaner\AdwCleaner[R0].txt - [740 bytes] - [06/06/2015 20:07:35]
C:\AdwCleaner\AdwCleaner[R1].txt - [852 bytes] - [08/07/2015 18:50:30]
C:\AdwCleaner\AdwCleaner[R2].txt - [966 bytes] - [22/07/2015 23:33:59]
C:\AdwCleaner\AdwCleaner[R3].txt - [1082 bytes] - [24/07/2015 21:12:10]
C:\AdwCleaner\AdwCleaner[R4].txt - [1203 bytes] - [11/08/2015 22:51:04]
C:\AdwCleaner\AdwCleaner[R5].txt - [1313 bytes] - [21/11/2015 16:50:18]
C:\AdwCleaner\AdwCleaner[S0].txt - [801 bytes] - [06/06/2015 20:08:37]
C:\AdwCleaner\AdwCleaner[S1].txt - [2921 bytes] - [08/07/2015 18:51:07]
C:\AdwCleaner\AdwCleaner[S2].txt - [1027 bytes] - [22/07/2015 23:34:38]
C:\AdwCleaner\AdwCleaner[S3].txt - [1145 bytes] - [24/07/2015 21:12:36]
C:\AdwCleaner\AdwCleaner[S4].txt - [1266 bytes] - [11/08/2015 22:52:18]
C:\AdwCleaner\AdwCleaner[S5].txt - [1376 bytes] - [21/11/2015 16:50:45]
C:\AdwCleaner\AdwCleaner[S7].txt - [642 bytes] - [07/01/2016 00:32:36]
########## EOF - C:\AdwCleaner\AdwCleaner[C1].txt - [1944 bytes] ##########
Re: Zasekany notebook
- spuste dvojklikem a extrahujte na plochu
- kliknete na Next
- aktualizujte virovou databazi klikem na Update a pokracujte na Next
- vsechny 3 moznosti nechte zaskrtnute a zvolte Scan (potrva cca 20 minut)
- zatrhnete vsechny nalezy a take zkontrolujte zatrzitko u Create Restore Point
- kliknete na Cleanup a souhlaste s restartem - Yes
- obsah logu ulozene na plose v mbar\mbar-log-2015-mm-dd (hh-mm-ss).txt vlozte do pristi odpovedi
Pokud je cokoliv nejasného, ihned se ptej.
V případě spokojenosti prosím podpořte forum.
Pro dotazy, které se nehodí na forum, je možné využít altrokzavináčforum.viry.cz
Máš-li chuť pomáhat návštěvníkům tohoto fora, přihlas se do naší školičky.
V případě spokojenosti prosím podpořte forum.
Pro dotazy, které se nehodí na forum, je možné využít altrokzavináčforum.viry.cz
Máš-li chuť pomáhat návštěvníkům tohoto fora, přihlas se do naší školičky.
Re: Zasekany notebook
Nic to nenaslo, tady vypis z logu:
Malwarebytes Anti-Rootkit BETA 1.9.3.1001
www.malwarebytes.org
Database version:
main: v2016.03.30.08
rootkit: v2016.03.30.01
Windows 8.1 x64 NTFS
Internet Explorer 11.0.9600.17728
Blaze :: IDEA-PC [administrator]
31. 3. 2016 1:35:12
mbar-log-2016-03-31 (01-35-12).txt
Scan type: Quick scan
Scan options enabled: Anti-Rootkit | Drivers | MBR | Physical Sectors | Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken
Scan options disabled:
Objects scanned: 395464
Time elapsed: 39 minute(s), 21 second(s)
Memory Processes Detected: 0
(No malicious items detected)
Memory Modules Detected: 0
(No malicious items detected)
Registry Keys Detected: 0
(No malicious items detected)
Registry Values Detected: 0
(No malicious items detected)
Registry Data Items Detected: 0
(No malicious items detected)
Folders Detected: 0
(No malicious items detected)
Files Detected: 0
(No malicious items detected)
Physical Sectors Detected: 0
(No malicious items detected)
(end)
Malwarebytes Anti-Rootkit BETA 1.9.3.1001
www.malwarebytes.org
Database version:
main: v2016.03.30.08
rootkit: v2016.03.30.01
Windows 8.1 x64 NTFS
Internet Explorer 11.0.9600.17728
Blaze :: IDEA-PC [administrator]
31. 3. 2016 1:35:12
mbar-log-2016-03-31 (01-35-12).txt
Scan type: Quick scan
Scan options enabled: Anti-Rootkit | Drivers | MBR | Physical Sectors | Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken
Scan options disabled:
Objects scanned: 395464
Time elapsed: 39 minute(s), 21 second(s)
Memory Processes Detected: 0
(No malicious items detected)
Memory Modules Detected: 0
(No malicious items detected)
Registry Keys Detected: 0
(No malicious items detected)
Registry Values Detected: 0
(No malicious items detected)
Registry Data Items Detected: 0
(No malicious items detected)
Folders Detected: 0
(No malicious items detected)
Files Detected: 0
(No malicious items detected)
Physical Sectors Detected: 0
(No malicious items detected)
(end)
Re: Zasekany notebook
Pozn. pri druhem a dalsim spusteni FRST je pro vytvoreni logu Addition.txt nutne tuto volbu explicitne zatrhnout pred zacatkem skenu.
Pokud je cokoliv nejasného, ihned se ptej.
V případě spokojenosti prosím podpořte forum.
Pro dotazy, které se nehodí na forum, je možné využít altrokzavináčforum.viry.cz
Máš-li chuť pomáhat návštěvníkům tohoto fora, přihlas se do naší školičky.
V případě spokojenosti prosím podpořte forum.
Pro dotazy, které se nehodí na forum, je možné využít altrokzavináčforum.viry.cz
Máš-li chuť pomáhat návštěvníkům tohoto fora, přihlas se do naší školičky.
Re: Zasekany notebook
LOG FRST:
Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version:05-03-2016 01
Ran by Blaze (administrator) on IDEA-PC (31-03-2016 20:21:54)
Running from C:\Users\Blaze\Desktop
Loaded Profiles: Blaze (Available Profiles: Blaze)
Platform: Windows 8.1 (X64) Language: Čeština (Česká republika)
Internet Explorer Version 11 (Default browser: FF)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/33 ... scan-tool/
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
(Intel(R) Corporation) C:\Program Files\Intel\WiFi\bin\EvtEng.exe
(Diskeeper Corporation) C:\Program Files\Diskeeper Corporation\ExpressCache\ExpressCache.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe
(Intel(R) Corporation) C:\Program Files\Intel\iCLS Client\HeciServer.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\Jhi_service.exe
(LogMeIn, Inc.) C:\Program Files (x86)\LogMeIn Hamachi\LMIGuardianSvc.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamService.exe
() C:\Windows\System32\PnkBstrA.exe
() C:\Program Files (x86)\Razer\Razer Services\GSS\GameScannerService.exe
(Intel(R) Corporation) C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\MsMpEng.exe
(Intel® Corporation) C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe
(LogMeIn Inc.) C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamNetworkService.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\NisSrv.exe
(Motorola Solutions, Inc.) C:\Program Files (x86)\Intel\Bluetooth\devmonsrv.exe
(Motorola Solutions, Inc.) C:\Program Files (x86)\Intel\Bluetooth\obexsrv.exe
(Intel Corporation) C:\Program Files\Intel\BluetoothHS\BTHSAmpPalService.exe
(Intel(R) Corporation) C:\Program Files\Intel\BluetoothHS\BTHSSecurityMgr.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(Microsoft Corporation) C:\Windows\System32\wlanext.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamUserAgent.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
(Realtek semiconductor) C:\Windows\RTFTrack.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
() C:\Program Files\Realtek\Audio\HDA\FMAPP.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
(Synaptics) C:\Program Files\Synaptics\SynTP\SynLenovoGestureMgr.exe
(Microsoft Corporation) C:\Windows\System32\rundll32.exe
(Lenovo) C:\Program Files\Lenovo\Onekey Theater\OnekeyStudio.exe
(Lenovo (Beijing) Limited) C:\Program Files (x86)\Lenovo\Energy Management\Energy Management.exe
(Lenovo(beijing) Limited) C:\Program Files (x86)\Lenovo\Energy Management\utility.exe
(Valve Corporation) C:\Program Files (x86)\Steam\Steam.exe
(Dolby Laboratories Inc.) C:\Program Files (x86)\Dolby Home Theater v4\pcee4.exe
(Razer Inc.) C:\Program Files (x86)\Razer\Synapse\RzSynapse.exe
(LogMeIn Inc.) C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe
(CyberLink) C:\Program Files (x86)\Lenovo\YouCam\YCMMirage.exe
(Valve Corporation) C:\Program Files (x86)\Steam\bin\steamwebhelper.exe
(Valve Corporation) C:\Program Files (x86)\Common Files\Steam\SteamService.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
(Valve Corporation) C:\Program Files (x86)\Steam\bin\steamwebhelper.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
(TeamSpeak Systems GmbH) C:\Program Files\TeamSpeak 3 Client\ts3client_win64.exe
(forum.viry.cz) C:\Users\Blaze\Desktop\FRSTLauncher.exe
==================== Registry (Whitelisted) ===========================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [RtsFT] => C:\windows\RTFTrack.exe [6334096 2012-08-06] (Realtek semiconductor)
HKLM\...\Run: [RtHDVCpl] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [12937872 2012-07-27] (Realtek Semiconductor)
HKLM\...\Run: [RtHDVBg_Dolby] => C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [1214608 2012-07-10] (Realtek Semiconductor)
HKLM\...\Run: [SynLenovoGestureMgr] => C:\Program Files\Synaptics\SynTP\SynLenovoGestureMgr.exe [665400 2012-08-16] (Synaptics)
HKLM\...\Run: [BTMTrayAgent] => rundll32.exe "C:\Program Files (x86)\Intel\Bluetooth\btmshell.dll",TrayApp
HKLM\...\Run: [OnekeyStudio] => C:\Program Files\Lenovo\Onekey Theater\OnekeyStudio.exe [4196432 2012-08-10] (Lenovo)
HKLM\...\Run: [Energy Management] => C:\Program Files (x86)\Lenovo\Energy Management\Energy Management.exe [17080376 2015-01-23] (Lenovo (Beijing) Limited)
HKLM\...\Run: [EnergyUtility] => C:\Program Files (x86)\Lenovo\Energy Management\Utility.exe [191544 2015-01-23] (Lenovo(beijing) Limited)
HKLM\...\Run: [NvBackend] => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe [2396096 2016-03-30] (NVIDIA Corporation)
HKLM\...\Run: [ShadowPlay] => "C:\WINDOWS\system32\rundll32.exe" C:\WINDOWS\system32\nvspcap64.dll,ShadowPlayOnSystemStart
HKLM\...\Run: [SynTPEnh] => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2916152 2012-08-16] (Synaptics Incorporated)
HKLM-x32\...\Run: [IAStorIcon] => C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [277504 2012-07-09] (Intel Corporation)
HKLM-x32\...\Run: [Dolby Home Theater v4] => C:\Program Files (x86)\Dolby Home Theater v4\pcee4.exe [508656 2012-07-26] (Dolby Laboratories Inc.)
HKLM-x32\...\Run: [YouCam Mirage] => C:\Program Files (x86)\Lenovo\YouCam\YCMMirage.exe [136488 2012-07-27] (CyberLink)
HKLM-x32\...\Run: [YouCam Tray] => C:\Program Files (x86)\Lenovo\YouCam\YouCamTray.exe [167024 2012-07-27] (CyberLink Corp.)
HKLM-x32\...\Run: [] => [X]
HKLM-x32\...\Run: [Razer Synapse] => C:\Program Files (x86)\Razer\Synapse\RzSynapse.exe [592704 2015-09-29] (Razer Inc.)
HKLM-x32\...\Run: [LogMeIn Hamachi Ui] => C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe [5565448 2015-11-12] (LogMeIn Inc.)
HKU\S-1-5-21-2968257316-2402521077-608179223-1002\...\Run: [Steam] => C:\Program Files (x86)\Steam\steam.exe [3077712 2016-03-28] (Valve Corporation)
AppInit_DLLs: C:\PROGRA~2\NVIDIA~1\3DVISI~1\NVSTIN~1.DLL => No File
ShellIconOverlayIdentifiers: [SugarSyncBackedUp] -> {0C4A258A-3F3B-4FFF-80A7-9B3BEC139472} => C:\Program Files (x86)\SugarSync\SugarSyncShellExt_x64.dll [2012-05-14] (SugarSync, Inc.)
ShellIconOverlayIdentifiers: [SugarSyncPending] -> {62CCD8E3-9C21-41E1-B55E-1E26DFC68511} => C:\Program Files (x86)\SugarSync\SugarSyncShellExt_x64.dll [2012-05-14] (SugarSync, Inc.)
ShellIconOverlayIdentifiers: [SugarSyncRoot] -> {A759AFF6-5851-457D-A540-F4ECED148351} => C:\Program Files (x86)\SugarSync\SugarSyncShellExt_x64.dll [2012-05-14] (SugarSync, Inc.)
ShellIconOverlayIdentifiers: [SugarSyncShared] -> {1574C9EF-7D58-488F-B358-8B78C1538F51} => C:\Program Files (x86)\SugarSync\SugarSyncShellExt_x64.dll [2012-05-14] (SugarSync, Inc.)
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
Tcpip\Parameters: [DhcpNameServer] 192.168.1.1
Tcpip\..\Interfaces\{34F4C0CD-C847-4240-A11F-48469FB13C46}: [DhcpNameServer] 77.242.95.5 81.200.55.34
Tcpip\..\Interfaces\{599265BF-420E-41DF-860E-E9D872006E78}: [DhcpNameServer] 192.168.1.1
Internet Explorer:
==================
HKU\S-1-5-21-2968257316-2402521077-608179223-1002\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://lenovo13.msn.com
HKU\S-1-5-21-2968257316-2402521077-608179223-1002\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://lenovo13.msn.com
HKU\S-1-5-21-2968257316-2402521077-608179223-1002\Software\Microsoft\Internet Explorer\Main,Secondary Start Pages = hxxp://www.lenovo.com
HKU\S-1-5-21-2968257316-2402521077-608179223-1002\Software\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = hxxp://www.lenovo.com
SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-21-2968257316-2402521077-608179223-1002 -> {3676BAB6-88A8-4791-BB0D-29235C336008} URL =
FireFox:
========
FF ProfilePath: C:\Users\Blaze\AppData\Roaming\Mozilla\Firefox\Profiles\cwl9atgv.default-1428576093703
FF Homepage: hxxps://seznam.cz/
FF Plugin: @adobe.com/FlashPlayer -> C:\WINDOWS\system32\Macromed\Flash\NPSWF64_21_0_0_197.dll [2016-03-23] ()
FF Plugin: @esn/npbattlelog,version=2.7.1 -> C:\Program Files (x86)\Battlelog Web Plugins\2.7.1\npbattlelogx64.dll [2015-04-30] (EA Digital Illusions CE AB)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\WINDOWS\SysWOW64\Macromed\Flash\NPSWF32_21_0_0_197.dll [2016-03-23] ()
FF Plugin-x32: @esn/npbattlelog,version=2.7.1 -> C:\Program Files (x86)\Battlelog Web Plugins\2.7.1\npbattlelog.dll [2015-04-30] (EA Digital Illusions CE AB)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=2.1.42 -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll [2012-06-07] (Intel Corporation)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll [2012-06-07] (Intel Corporation)
FF Plugin-x32: @nvidia.com/3DVision -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll [2016-03-22] (NVIDIA Corporation)
FF Plugin-x32: @nvidia.com/3DVisionStreaming -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll [2016-03-22] (NVIDIA Corporation)
FF Plugin-x32: @raidcall.en/RCplugin -> C:\Users\Blaze\AppData\Roaming\raidcall\plugins\nprcplugin.dll [2014-05-27] (Raidcall)
FF Extension: Flash Video Downloader - YouTube HD Download [4K] - C:\Users\Blaze\AppData\Roaming\Mozilla\Firefox\Profiles\cwl9atgv.default-1428576093703\extensions\artur.dubovoy@gmail.com [2016-03-29]
FF Extension: Adblock Plus - C:\Users\Blaze\AppData\Roaming\Mozilla\Firefox\Profiles\cwl9atgv.default-1428576093703\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2016-02-24]
FF Extension: Default - C:\Program Files (x86)\Mozilla Firefox\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}.xpi [2016-03-19] [not signed]
FF HKLM-x32\...\Thunderbird\Extensions: [msktbird@mcafee.com] - C:\Program Files\McAfee\MSK => not found
==================== Services (Whitelisted) ========================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
S3 BEService; C:\Program Files (x86)\Common Files\BattlEye\BEService.exe [1345056 2016-02-11] ()
R2 ExpressCache; C:\Program Files\Diskeeper Corporation\ExpressCache\ExpressCache.exe [79664 2012-03-30] (Diskeeper Corporation)
R2 GfExperienceService; C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe [1163200 2016-03-30] (NVIDIA Corporation)
R2 IAStorDataMgrSvc; C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe [7168 2012-07-09] (Intel Corporation) [File not signed]
R2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [166720 2012-06-25] (Intel Corporation)
R2 LMIGuardianSvc; C:\Program Files (x86)\LogMeIn Hamachi\LMIGuardianSvc.exe [417552 2015-11-12] (LogMeIn, Inc.)
S2 MBAMService; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe [1133880 2015-06-18] (Malwarebytes Corporation)
S3 MyWiFiDHCPDNS; C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe [273136 2013-08-28] ()
R2 NvNetworkService; C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe [1879488 2016-03-30] (NVIDIA Corporation)
R3 NvStreamNetworkSvc; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamNetworkService.exe [3632576 2016-03-30] (NVIDIA Corporation)
R2 NvStreamSvc; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamService.exe [2521024 2016-03-30] (NVIDIA Corporation)
S3 Origin Client Service; C:\Program Files (x86)\Origin\OriginClientService.exe [2119688 2016-03-30] (Electronic Arts)
R2 PnkBstrA; C:\WINDOWS\system32\PnkBstrA.exe [76152 2016-03-25] ()
R2 PnkBstrA; C:\WINDOWS\SysWOW64\PnkBstrA.exe [76888 2016-03-25] ()
R2 Razer Game Scanner Service; C:\Program Files (x86)\Razer\Razer Services\GSS\GameScannerService.exe [187048 2015-06-23] ()
R3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [366520 2015-04-16] (Microsoft Corporation)
R2 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [23792 2015-04-16] (Microsoft Corporation)
R2 ZeroConfigService; C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe [3378416 2013-08-28] (Intel® Corporation)
===================== Drivers (Whitelisted) ==========================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
S0 ebdrv; C:\Windows\System32\drivers\evbda.sys [3357024 2013-08-22] (Broadcom Corporation)
R1 excfs; C:\Windows\System32\DRIVERS\excfs.sys [23344 2012-03-30] (Diskeeper Corporation)
R0 excsd; C:\Windows\System32\DRIVERS\excsd.sys [95024 2012-03-30] (Diskeeper Corporation)
R3 Hamachi; C:\Windows\system32\DRIVERS\Hamdrv.sys [45680 2015-11-12] (LogMeIn Inc.)
R3 MBAMProtector; C:\WINDOWS\system32\drivers\mbam.sys [25816 2015-06-18] (Malwarebytes Corporation)
S3 MBAMWebAccessControl; C:\WINDOWS\system32\drivers\mwac.sys [64216 2015-06-18] (Malwarebytes Corporation)
R3 NETwNe64; C:\Windows\system32\DRIVERS\Netwew00.sys [3345376 2013-10-08] (Intel Corporation)
R3 NvStreamKms; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys [26560 2016-03-30] (NVIDIA Corporation)
R3 nvvad_WaveExtensible; C:\Windows\system32\drivers\nvvad64v.sys [56384 2016-03-21] (NVIDIA Corporation)
R3 rtsuvc; C:\Windows\system32\DRIVERS\rtsuvc.sys [8226832 2012-08-06] (Realtek Semiconductor Corp.)
R2 rzpmgrk; C:\WINDOWS\system32\drivers\rzpmgrk.sys [37184 2015-06-12] (Razer, Inc.)
R2 rzpnk; C:\WINDOWS\system32\drivers\rzpnk.sys [129472 2015-06-27] (Razer, Inc.)
R3 SmbDrvI; C:\Windows\system32\DRIVERS\Smb_driver_Intel.sys [43832 2012-08-16] (Synaptics Incorporated)
S0 WdBoot; C:\Windows\System32\drivers\WdBoot.sys [44024 2015-04-16] (Microsoft Corporation)
R0 WdFilter; C:\Windows\System32\drivers\WdFilter.sys [264000 2015-04-16] (Microsoft Corporation)
R3 WdNisDrv; C:\Windows\System32\Drivers\WdNisDrv.sys [114496 2015-04-16] (Microsoft Corporation)
S3 wsvd; C:\Windows\system32\DRIVERS\wsvd.sys [102376 2012-06-14] ("CyberLink)
==================== NetSvcs (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
==================== One Month Created files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2016-03-31 20:21 - 2016-03-31 20:22 - 00016294 _____ C:\Users\Blaze\Desktop\FRST.txt
2016-03-31 20:21 - 2016-03-31 20:21 - 00000000 ____D C:\FRST
2016-03-31 20:17 - 2016-03-31 20:17 - 00112640 _____ (forum.viry.cz) C:\Users\Blaze\Desktop\FRSTLauncher.exe
2016-03-31 20:13 - 2016-03-31 20:13 - 02374144 _____ (Farbar) C:\Users\Blaze\Desktop\FRST64.exe
2016-03-31 02:55 - 2016-03-31 02:55 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Vulkan
2016-03-31 02:55 - 2016-03-22 04:10 - 00112184 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvStreaming.exe
2016-03-31 02:54 - 2016-03-31 02:54 - 00000000 ____D C:\WINDOWS\LastGood
2016-03-31 02:52 - 2016-03-22 06:12 - 42923576 _____ C:\WINDOWS\system32\nvcompiler.dll
2016-03-31 02:52 - 2016-03-22 06:12 - 37567424 _____ C:\WINDOWS\SysWOW64\nvcompiler.dll
2016-03-31 02:52 - 2016-03-22 06:12 - 31555008 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvoglv64.dll
2016-03-31 02:52 - 2016-03-22 06:12 - 25321408 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvoglv32.dll
2016-03-31 02:52 - 2016-03-22 06:12 - 21355248 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvopencl.dll
2016-03-31 02:52 - 2016-03-22 06:12 - 20897416 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvcuda.dll
2016-03-31 02:52 - 2016-03-22 06:12 - 19004040 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvwgf2umx.dll
2016-03-31 02:52 - 2016-03-22 06:12 - 17748712 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvopencl.dll
2016-03-31 02:52 - 2016-03-22 06:12 - 17342392 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvcuda.dll
2016-03-31 02:52 - 2016-03-22 06:12 - 17248408 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvd3dumx.dll
2016-03-31 02:52 - 2016-03-22 06:12 - 16446032 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvwgf2um.dll
2016-03-31 02:52 - 2016-03-22 06:12 - 14128840 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvd3dum.dll
2016-03-31 02:52 - 2016-03-22 06:12 - 12567608 _____ (NVIDIA Corporation) C:\WINDOWS\system32\Drivers\nvlddmkm.sys
2016-03-31 02:52 - 2016-03-22 06:12 - 10550736 _____ C:\WINDOWS\system32\nvptxJitCompiler.dll
2016-03-31 02:52 - 2016-03-22 06:12 - 08659472 _____ C:\WINDOWS\SysWOW64\nvptxJitCompiler.dll
2016-03-31 02:52 - 2016-03-22 06:12 - 03714472 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvapi64.dll
2016-03-31 02:52 - 2016-03-22 06:12 - 03286992 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvapi.dll
2016-03-31 02:52 - 2016-03-22 06:12 - 03235896 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvcuvid.dll
2016-03-31 02:52 - 2016-03-22 06:12 - 02809280 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvcuvid.dll
2016-03-31 02:52 - 2016-03-22 06:12 - 01924152 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvdispco6436472.dll
2016-03-31 02:52 - 2016-03-22 06:12 - 01573432 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvdispgenco6436472.dll
2016-03-31 02:52 - 2016-03-22 06:12 - 00959544 _____ (NVIDIA Corporation) C:\WINDOWS\system32\NvFBC64.dll
2016-03-31 02:52 - 2016-03-22 06:12 - 00889400 _____ (NVIDIA Corporation) C:\WINDOWS\system32\NvIFR64.dll
2016-03-31 02:52 - 2016-03-22 06:12 - 00753208 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\NvFBC.dll
2016-03-31 02:52 - 2016-03-22 06:12 - 00695864 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\NvIFR.dll
2016-03-31 02:52 - 2016-03-22 06:12 - 00678520 _____ C:\WINDOWS\system32\nvfatbinaryLoader.dll
2016-03-31 02:52 - 2016-03-22 06:12 - 00571912 _____ C:\WINDOWS\SysWOW64\nvfatbinaryLoader.dll
2016-03-31 02:52 - 2016-03-22 06:12 - 00501896 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvEncodeAPI64.dll
2016-03-31 02:52 - 2016-03-22 06:12 - 00425016 _____ (NVIDIA Corporation) C:\WINDOWS\system32\NvIFROpenGL.dll
2016-03-31 02:52 - 2016-03-22 06:12 - 00423080 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvEncodeAPI.dll
2016-03-31 02:52 - 2016-03-22 06:12 - 00377792 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\NvIFROpenGL.dll
2016-03-31 02:52 - 2016-03-22 06:12 - 00000139 _____ C:\WINDOWS\SysWOW64\nv-vk32.json
2016-03-31 02:52 - 2016-03-22 06:12 - 00000139 _____ C:\WINDOWS\system32\nv-vk64.json
2016-03-31 02:33 - 2016-03-31 02:33 - 00000000 ____D C:\WINDOWS\LastGood.Tmp
2016-03-31 02:33 - 2016-03-21 22:01 - 00109632 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvaudcap64v.dll
2016-03-31 02:33 - 2016-03-21 22:01 - 00100416 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvaudcap32v.dll
2016-03-31 02:33 - 2016-03-21 22:01 - 00056384 _____ (NVIDIA Corporation) C:\WINDOWS\system32\Drivers\nvvad64v.sys
2016-03-31 01:35 - 2016-03-31 02:32 - 00000000 ____D C:\ProgramData\Malwarebytes' Anti-Malware (portable)
2016-03-31 01:33 - 2016-03-31 02:32 - 00000000 ____D C:\Users\Blaze\Desktop\mbar
2016-03-31 01:32 - 2016-03-31 01:32 - 16563352 _____ (Malwarebytes Corp.) C:\Users\Blaze\Desktop\mbar-1.09.3.1001.exe
2016-03-31 01:03 - 2016-03-31 01:03 - 03102720 _____ C:\Users\Blaze\Downloads\adwcleaner_5.108.exe
2016-03-30 22:29 - 2016-03-30 22:29 - 00000000 ____D C:\rsit
2016-03-29 00:13 - 2016-03-29 00:37 - 411326664 _____ C:\Users\Blaze\Downloads\loves01e10.mp4
2016-03-28 20:39 - 2016-03-28 20:54 - 228736064 _____ C:\Users\Blaze\Downloads\loves01e09.mp4
2016-03-28 08:45 - 2016-03-28 08:48 - 221898939 _____ C:\Users\Blaze\Downloads\loves01e07.mp4
2016-03-28 07:40 - 2016-03-28 07:44 - 290769501 _____ C:\Users\Blaze\Downloads\loves01e06.mp4
2016-03-28 06:34 - 2016-03-28 06:37 - 261010205 _____ C:\Users\Blaze\Downloads\loves01e05.mp4
2016-03-28 05:35 - 2016-03-28 05:38 - 286555922 _____ C:\Users\Blaze\Downloads\loves01e04.mp4
2016-03-28 05:00 - 2016-03-28 05:03 - 259122073 _____ C:\Users\Blaze\Downloads\loves01e03.mp4
2016-03-25 18:28 - 2016-03-25 18:28 - 00076152 _____ C:\WINDOWS\system32\PnkBstrA.exe
2016-03-25 10:36 - 2016-03-25 10:41 - 00000000 ____D C:\Users\Blaze\Documents\Battlefield 4
2016-03-25 10:36 - 2016-03-25 10:36 - 00000000 ____D C:\Users\Blaze\AppData\Local\ESN
2016-03-25 10:35 - 2016-03-25 10:35 - 01640768 _____ C:\Users\Blaze\Downloads\battlelog-web-plugins_2.7.1_162(1).exe
2016-03-25 09:50 - 2016-03-25 09:50 - 00001263 _____ C:\Users\Public\Desktop\Battlefield 4.lnk
2016-03-25 09:50 - 2016-03-25 09:50 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Battlefield 4
2016-03-23 16:49 - 2016-03-31 02:55 - 00000000 ____D C:\Program Files (x86)\VulkanRT
2016-03-23 16:49 - 2016-03-23 16:49 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Vulkan 1.0.3.0
2016-03-23 16:49 - 2016-03-16 23:30 - 00128792 _____ C:\WINDOWS\SysWOW64\vulkan-1.dll
2016-03-23 16:49 - 2016-03-16 23:29 - 00127768 _____ C:\WINDOWS\system32\vulkan-1.dll
2016-03-23 16:49 - 2016-03-16 23:29 - 00041752 _____ C:\WINDOWS\SysWOW64\vulkaninfo.exe
2016-03-23 16:49 - 2016-03-16 23:28 - 00045848 _____ C:\WINDOWS\system32\vulkaninfo.exe
2016-03-23 16:46 - 2016-03-08 12:07 - 01924152 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvdispco6436451.dll
2016-03-23 16:46 - 2016-03-08 12:07 - 01571776 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvdispgenco6436451.dll
2016-03-23 15:40 - 2016-03-23 15:40 - 00000000 ____D C:\Users\Blaze\AppData\Local\Victory
2016-03-23 15:40 - 2016-03-23 15:40 - 00000000 ____D C:\Users\Blaze\AppData\Local\UnrealEngine
2016-03-23 15:40 - 2015-08-22 15:42 - 00901264 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ucrtbase.dll
2016-03-23 15:40 - 2015-08-22 15:42 - 00066400 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\api-ms-win-crt-private-l1-1-0.dll
2016-03-23 15:40 - 2015-08-22 15:42 - 00022368 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\api-ms-win-crt-math-l1-1-0.dll
2016-03-23 15:40 - 2015-08-22 15:42 - 00019808 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\api-ms-win-crt-multibyte-l1-1-0.dll
2016-03-23 15:40 - 2015-08-22 15:42 - 00017760 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\api-ms-win-crt-string-l1-1-0.dll
2016-03-23 15:40 - 2015-08-22 15:42 - 00017760 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\api-ms-win-crt-stdio-l1-1-0.dll
2016-03-23 15:40 - 2015-08-22 15:42 - 00016224 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\api-ms-win-crt-runtime-l1-1-0.dll
2016-03-23 15:40 - 2015-08-22 15:42 - 00015712 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\api-ms-win-crt-convert-l1-1-0.dll
2016-03-23 15:40 - 2015-08-22 15:42 - 00014176 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\api-ms-win-crt-time-l1-1-0.dll
2016-03-23 15:40 - 2015-08-22 15:42 - 00013664 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\api-ms-win-crt-filesystem-l1-1-0.dll
2016-03-23 15:40 - 2015-08-22 15:42 - 00012640 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\api-ms-win-crt-process-l1-1-0.dll
2016-03-23 15:40 - 2015-08-22 15:42 - 00012640 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\api-ms-win-crt-heap-l1-1-0.dll
2016-03-23 15:40 - 2015-08-22 15:42 - 00012640 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\api-ms-win-crt-conio-l1-1-0.dll
2016-03-23 15:40 - 2015-08-22 15:42 - 00012128 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\api-ms-win-crt-utility-l1-1-0.dll
2016-03-23 15:40 - 2015-08-22 15:42 - 00012128 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\api-ms-win-crt-locale-l1-1-0.dll
2016-03-23 15:40 - 2015-08-22 15:42 - 00012128 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\api-ms-win-crt-environment-l1-1-0.dll
2016-03-23 15:40 - 2015-08-22 15:35 - 00984448 _____ (Microsoft Corporation) C:\WINDOWS\system32\ucrtbase.dll
2016-03-23 15:40 - 2015-08-22 15:35 - 00063840 _____ (Microsoft Corporation) C:\WINDOWS\system32\api-ms-win-crt-private-l1-1-0.dll
2016-03-23 15:40 - 2015-08-22 15:35 - 00020832 _____ (Microsoft Corporation) C:\WINDOWS\system32\api-ms-win-crt-math-l1-1-0.dll
2016-03-23 15:40 - 2015-08-22 15:35 - 00019808 _____ (Microsoft Corporation) C:\WINDOWS\system32\api-ms-win-crt-multibyte-l1-1-0.dll
2016-03-23 15:40 - 2015-08-22 15:35 - 00017760 _____ (Microsoft Corporation) C:\WINDOWS\system32\api-ms-win-crt-string-l1-1-0.dll
2016-03-23 15:40 - 2015-08-22 15:35 - 00017760 _____ (Microsoft Corporation) C:\WINDOWS\system32\api-ms-win-crt-stdio-l1-1-0.dll
2016-03-23 15:40 - 2015-08-22 15:35 - 00016224 _____ (Microsoft Corporation) C:\WINDOWS\system32\api-ms-win-crt-runtime-l1-1-0.dll
2016-03-23 15:40 - 2015-08-22 15:35 - 00015712 _____ (Microsoft Corporation) C:\WINDOWS\system32\api-ms-win-crt-convert-l1-1-0.dll
2016-03-23 15:40 - 2015-08-22 15:35 - 00014176 _____ (Microsoft Corporation) C:\WINDOWS\system32\api-ms-win-crt-time-l1-1-0.dll
2016-03-23 15:40 - 2015-08-22 15:35 - 00013664 _____ (Microsoft Corporation) C:\WINDOWS\system32\api-ms-win-crt-filesystem-l1-1-0.dll
2016-03-23 15:40 - 2015-08-22 15:35 - 00012640 _____ (Microsoft Corporation) C:\WINDOWS\system32\api-ms-win-crt-process-l1-1-0.dll
2016-03-23 15:40 - 2015-08-22 15:35 - 00012640 _____ (Microsoft Corporation) C:\WINDOWS\system32\api-ms-win-crt-heap-l1-1-0.dll
2016-03-23 15:40 - 2015-08-22 15:35 - 00012640 _____ (Microsoft Corporation) C:\WINDOWS\system32\api-ms-win-crt-conio-l1-1-0.dll
2016-03-23 15:40 - 2015-08-22 15:35 - 00012128 _____ (Microsoft Corporation) C:\WINDOWS\system32\api-ms-win-crt-utility-l1-1-0.dll
2016-03-23 15:40 - 2015-08-22 15:35 - 00012128 _____ (Microsoft Corporation) C:\WINDOWS\system32\api-ms-win-crt-locale-l1-1-0.dll
2016-03-23 15:40 - 2015-08-22 15:35 - 00012128 _____ (Microsoft Corporation) C:\WINDOWS\system32\api-ms-win-crt-environment-l1-1-0.dll
2016-03-19 22:56 - 2016-03-20 16:31 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox
2016-03-16 23:30 - 2016-03-16 23:30 - 00128792 _____ C:\WINDOWS\SysWOW64\vulkan-1-1-0-5-1.dll
2016-03-16 23:29 - 2016-03-16 23:29 - 00127768 _____ C:\WINDOWS\system32\vulkan-1-1-0-5-1.dll
2016-03-16 23:29 - 2016-03-16 23:29 - 00041752 _____ C:\WINDOWS\SysWOW64\vulkaninfo-1-1-0-5-1.exe
2016-03-16 23:28 - 2016-03-16 23:28 - 00045848 _____ C:\WINDOWS\system32\vulkaninfo-1-1-0-5-1.exe
2016-03-13 21:22 - 2016-03-31 01:07 - 00000000 ____D C:\Program Files (x86)\Battlelog Web Plugins
2016-03-13 21:22 - 2016-03-13 21:22 - 01640768 _____ C:\Users\Blaze\Downloads\battlelog-web-plugins_2.7.1_162.exe
2016-03-13 21:19 - 2016-03-13 21:23 - 00000000 ____D C:\Users\Blaze\Documents\Battlefield 3
2016-03-13 20:44 - 2016-03-13 20:44 - 00001197 _____ C:\Users\Public\Desktop\Battlefield 3.lnk
2016-03-13 20:44 - 2016-03-13 20:44 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Battlefield 3
2016-03-13 20:04 - 2016-03-25 09:06 - 00000000 ____D C:\Program Files (x86)\Origin Games
2016-03-13 20:01 - 2016-03-13 21:19 - 00000000 ____D C:\Users\Blaze\AppData\Local\Origin
2016-03-13 20:00 - 2016-03-13 20:00 - 00001002 _____ C:\Users\Public\Desktop\Origin.lnk
2016-03-13 20:00 - 2016-03-13 20:00 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Origin
2016-03-13 19:58 - 2016-03-30 00:15 - 00000000 ____D C:\Program Files (x86)\Origin
2016-03-13 19:57 - 2016-03-13 19:58 - 31334856 _____ (Electronic Arts, Inc.) C:\Users\Blaze\Downloads\OriginThinSetup(1).exe
2016-03-13 16:09 - 2016-03-13 16:09 - 00001900 _____ C:\Users\Blaze\Downloads\SWAG.Stratis.rar
2016-03-02 02:44 - 2016-02-24 01:58 - 01922496 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvdispco6436200.dll
2016-03-02 02:44 - 2016-02-24 01:58 - 01571776 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvdispgenco6436200.dll
==================== One Month Modified files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2016-03-31 20:19 - 2015-04-09 11:10 - 00000000 ____D C:\Users\Blaze\AppData\Roaming\TS3Client
2016-03-31 20:00 - 2015-07-28 05:01 - 00003966 _____ C:\WINDOWS\System32\Tasks\User_Feed_Synchronization-{5075C313-9A99-4915-B33E-BFE454DDEDD3}
2016-03-31 19:59 - 2015-12-17 15:24 - 00000000 ____D C:\Users\Blaze\AppData\Local\LogMeIn Hamachi
2016-03-31 19:59 - 2015-04-09 19:46 - 00000000 ____D C:\Program Files (x86)\Steam
2016-03-31 08:55 - 2015-05-14 17:54 - 00000914 _____ C:\WINDOWS\Tasks\Adobe Flash Player Updater.job
2016-03-31 08:09 - 2015-04-09 19:30 - 00003598 _____ C:\WINDOWS\System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-2968257316-2402521077-608179223-1002
2016-03-31 03:27 - 2015-04-23 11:29 - 00000080 _____ C:\Users\Blaze\AppData\Local剜捯獫慴慇敭屳呇⁁屖湥楴汴浥湥湩潦
2016-03-31 03:07 - 2015-01-23 18:35 - 00000000 ____D C:\ProgramData\NVIDIA
2016-03-31 03:07 - 2013-08-22 16:45 - 00000006 ____H C:\WINDOWS\Tasks\SA.DAT
2016-03-31 03:01 - 2015-12-28 22:28 - 00000000 ____D C:\Users\Blaze\AppData\Local\CrashDumps
2016-03-31 02:55 - 2015-04-16 00:01 - 00000000 ____D C:\ProgramData\NVIDIA Corporation
2016-03-31 02:55 - 2013-08-22 15:36 - 00000000 ____D C:\WINDOWS\Inf
2016-03-31 02:54 - 2015-04-16 00:01 - 00000000 ____D C:\Program Files\NVIDIA Corporation
2016-03-31 02:44 - 2013-08-22 15:25 - 00262144 ___SH C:\WINDOWS\system32\config\BBI
2016-03-31 01:35 - 2015-07-22 23:38 - 00192216 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\MBAMSwissArmy.sys
2016-03-31 01:34 - 2015-07-22 23:38 - 00109272 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\mbamchameleon.sys
2016-03-31 01:14 - 2015-07-15 11:09 - 00000000 ____D C:\Program Files (x86)\Bloody5
2016-03-31 01:14 - 2014-11-21 06:53 - 01749406 _____ C:\WINDOWS\system32\PerfStringBackup.INI
2016-03-31 01:14 - 2014-11-21 06:10 - 00740962 _____ C:\WINDOWS\system32\perfh005.dat
2016-03-31 01:14 - 2014-11-21 06:10 - 00152146 _____ C:\WINDOWS\system32\perfc005.dat
2016-03-31 01:06 - 2015-06-06 20:07 - 00000000 ____D C:\AdwCleaner
2016-03-31 01:05 - 2015-04-23 08:12 - 00000000 ____D C:\ProgramData\Origin
2016-03-30 23:57 - 2015-04-23 08:50 - 00226168 _____ C:\WINDOWS\SysWOW64\PnkBstrB.exe
2016-03-30 23:51 - 2015-04-23 08:50 - 00226168 _____ C:\WINDOWS\SysWOW64\PnkBstrB.ex0
2016-03-30 22:29 - 2015-04-10 11:00 - 00000000 ____D C:\Program Files\trend micro
2016-03-30 06:07 - 2015-04-09 12:13 - 00000000 ____D C:\Users\Blaze\AppData\Local\ArmA 2 OA
2016-03-30 05:43 - 2015-04-23 11:31 - 00001754 _____ C:\Users\Blaze\Desktop\66M3-QGTZ-YJVP-VHFK.txt
2016-03-30 03:06 - 2015-04-10 13:39 - 01373680 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvspcap.dll
2016-03-30 03:06 - 2015-04-10 13:39 - 01316000 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvspbridge.dll
2016-03-30 03:05 - 2015-11-21 16:19 - 00112216 _____ C:\WINDOWS\system32\NvRtmpStreamer64.dll
2016-03-30 03:05 - 2015-04-10 13:39 - 01767248 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvspcap64.dll
2016-03-30 03:05 - 2015-04-10 13:39 - 01756424 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvspbridge64.dll
2016-03-29 19:03 - 2015-05-10 14:56 - 00000000 ____D C:\Users\Blaze\AppData\Local\Arma 3
2016-03-29 05:43 - 2015-04-09 11:13 - 00000000 ____D C:\Users\Blaze\AppData\Roaming\Skype
2016-03-29 05:35 - 2015-04-09 12:48 - 00000000 ____D C:\Users\Blaze\AppData\Local\Battle.net
2016-03-29 05:09 - 2015-04-09 13:34 - 00000000 ____D C:\Program Files (x86)\World of Warcraft
2016-03-29 05:06 - 2015-04-09 12:47 - 00000000 ____D C:\Program Files (x86)\Battle.net
2016-03-29 00:41 - 2015-04-09 13:53 - 00000000 ____D C:\KMPlayer
2016-03-26 19:06 - 2015-04-23 11:28 - 00000000 ____D C:\Program Files\Rockstar Games
2016-03-26 19:06 - 2015-04-23 11:28 - 00000000 ____D C:\Program Files (x86)\Rockstar Games
2016-03-25 10:40 - 2015-04-23 20:04 - 00000000 ____D C:\Users\Blaze\AppData\Local\PunkBuster
2016-03-25 09:50 - 2015-04-23 08:50 - 00076888 _____ C:\WINDOWS\SysWOW64\PnkBstrA.exe
2016-03-25 09:50 - 2015-04-09 10:53 - 00000000 ____D C:\ProgramData\Package Cache
2016-03-25 03:09 - 2015-04-23 20:04 - 00348360 _____ C:\WINDOWS\SysWOW64\PnkBstrB.xtr
2016-03-23 23:55 - 2015-04-09 13:45 - 00003802 _____ C:\WINDOWS\System32\Tasks\Adobe Flash Player Updater
2016-03-23 15:40 - 2012-07-26 09:59 - 00000000 ____D C:\WINDOWS\CbsTemp
2016-03-23 02:48 - 2016-02-22 04:35 - 00000000 ____D C:\Program Files (x86)\A3Launcher
2016-03-22 06:12 - 2015-04-14 00:04 - 00037091 _____ C:\WINDOWS\system32\nvinfo.pb
2016-03-22 04:25 - 2015-12-27 07:29 - 00532536 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nv3dappshext.dll
2016-03-22 04:25 - 2015-12-27 07:29 - 00081856 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nv3dappshextr.dll
2016-03-22 04:25 - 2015-04-16 00:02 - 06369728 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvcpl.dll
2016-03-22 04:25 - 2015-04-16 00:02 - 02993088 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvsvc64.dll
2016-03-22 04:25 - 2015-04-16 00:02 - 02561472 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvsvcr.dll
2016-03-22 04:25 - 2015-04-16 00:02 - 01264064 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvvsvc.exe
2016-03-22 04:25 - 2015-04-16 00:02 - 00393784 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvmctray.dll
2016-03-22 04:25 - 2015-04-16 00:02 - 00123960 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\oemdspif.dll
2016-03-22 04:25 - 2015-04-16 00:02 - 00069568 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvshext.dll
2016-03-21 04:52 - 2015-04-16 00:12 - 00000000 ____D C:\Users\Blaze
2016-03-20 16:31 - 2015-04-09 19:44 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2016-03-18 20:10 - 2015-04-16 00:02 - 06253721 _____ C:\WINDOWS\system32\nvcoproc.bin
2016-03-13 22:50 - 2013-08-22 17:36 - 00000000 ___HD C:\Program Files\WindowsApps
2016-03-13 22:50 - 2013-08-22 17:36 - 00000000 ____D C:\WINDOWS\AppReadiness
2016-03-11 16:46 - 2015-05-10 14:56 - 00000000 ____D C:\Users\Blaze\Documents\Arma 3
2016-03-09 23:26 - 2015-04-09 11:12 - 00000000 ____D C:\ProgramData\Skype
2016-03-03 01:44 - 2015-04-09 12:48 - 00000000 ____D C:\Users\Blaze\AppData\Roaming\Battle.net
==================== Files in the root of some directories =======
2015-01-23 18:42 - 2015-01-23 18:42 - 0000000 ____H () C:\ProgramData\DP45977C.lfl
Some files in TEMP:
====================
C:\Users\Blaze\AppData\Local\Temp\libeay32.dll
C:\Users\Blaze\AppData\Local\Temp\mpam-d29af102.exe
C:\Users\Blaze\AppData\Local\Temp\msvcr120.dll
C:\Users\Blaze\AppData\Local\Temp\nvSCPAPI.dll
C:\Users\Blaze\AppData\Local\Temp\nvSCPAPI64.dll
C:\Users\Blaze\AppData\Local\Temp\nvSCPAPISvr.exe
C:\Users\Blaze\AppData\Local\Temp\nvStInst.exe
C:\Users\Blaze\AppData\Local\Temp\Razor_Latest.exe
C:\Users\Blaze\AppData\Local\Temp\SkypeSetup.exe
C:\Users\Blaze\AppData\Local\Temp\sonarinst.exe
C:\Users\Blaze\AppData\Local\Temp\sqlite3.dll
C:\Users\Blaze\AppData\Local\Temp\_unps.exe
==================== Bamital & volsnap =================
(There is no automatic fix for files that do not pass verification.)
C:\WINDOWS\system32\winlogon.exe => File is digitally signed
C:\WINDOWS\system32\wininit.exe => File is digitally signed
C:\WINDOWS\explorer.exe => File is digitally signed
C:\WINDOWS\SysWOW64\explorer.exe => File is digitally signed
C:\WINDOWS\system32\svchost.exe => File is digitally signed
C:\WINDOWS\SysWOW64\svchost.exe => File is digitally signed
C:\WINDOWS\system32\services.exe => File is digitally signed
C:\WINDOWS\system32\User32.dll => File is digitally signed
C:\WINDOWS\SysWOW64\User32.dll => File is digitally signed
C:\WINDOWS\system32\userinit.exe => File is digitally signed
C:\WINDOWS\SysWOW64\userinit.exe => File is digitally signed
C:\WINDOWS\system32\rpcss.dll => File is digitally signed
C:\WINDOWS\system32\dnsapi.dll => File is digitally signed
C:\WINDOWS\SysWOW64\dnsapi.dll => File is digitally signed
C:\WINDOWS\system32\Drivers\volsnap.sys => File is digitally signed
===***===***===***=== Extract of Additional scan result of Farbar Recovery Scan Tool ===***===***===***===
==================== Drive and Memory info ===================
==================== MBR and Partition Table ==================
==================== Scheduled Tasks (whitelisted) ==================
(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)
Task: C:\WINDOWS\Tasks\Adobe Flash Player Updater.job => C:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\WINDOWS\Tasks\Synaptics TouchPad Enhancements.job => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
==================== Alternate Data Streams (whitelisted) ==================
==================== Security Center ==================
AV: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
===***===***===***=== Supplementary Scan createdy by FRSTLauncher ===***===***===***===
Posledni aktualizace FRSTLauncheru: 25_11_2013 (01)
Posledni aktualizace Modifikacniho skriptu: 30_09_2013 (01)
***** Velikost "Plochy" *****
Velikost slozky "C:\Users\Blaze\Desktop" je 70 MB.
***** Startup Programs *****
***** Firewall rules *****
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
EnableFirewall REG_DWORD 0x1
DisableNotifications REG_DWORD 0x0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
EnableFirewall REG_DWORD 0x1
DisableNotifications REG_DWORD 0x0
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
***** System Restore *****
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"Generalize_DisableSR"=dword:00000000
==================== End Of Log ==============================
Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version:05-03-2016 01
Ran by Blaze (administrator) on IDEA-PC (31-03-2016 20:21:54)
Running from C:\Users\Blaze\Desktop
Loaded Profiles: Blaze (Available Profiles: Blaze)
Platform: Windows 8.1 (X64) Language: Čeština (Česká republika)
Internet Explorer Version 11 (Default browser: FF)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/33 ... scan-tool/
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
(Intel(R) Corporation) C:\Program Files\Intel\WiFi\bin\EvtEng.exe
(Diskeeper Corporation) C:\Program Files\Diskeeper Corporation\ExpressCache\ExpressCache.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe
(Intel(R) Corporation) C:\Program Files\Intel\iCLS Client\HeciServer.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\Jhi_service.exe
(LogMeIn, Inc.) C:\Program Files (x86)\LogMeIn Hamachi\LMIGuardianSvc.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamService.exe
() C:\Windows\System32\PnkBstrA.exe
() C:\Program Files (x86)\Razer\Razer Services\GSS\GameScannerService.exe
(Intel(R) Corporation) C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\MsMpEng.exe
(Intel® Corporation) C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe
(LogMeIn Inc.) C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamNetworkService.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\NisSrv.exe
(Motorola Solutions, Inc.) C:\Program Files (x86)\Intel\Bluetooth\devmonsrv.exe
(Motorola Solutions, Inc.) C:\Program Files (x86)\Intel\Bluetooth\obexsrv.exe
(Intel Corporation) C:\Program Files\Intel\BluetoothHS\BTHSAmpPalService.exe
(Intel(R) Corporation) C:\Program Files\Intel\BluetoothHS\BTHSSecurityMgr.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(Microsoft Corporation) C:\Windows\System32\wlanext.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamUserAgent.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
(Realtek semiconductor) C:\Windows\RTFTrack.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
() C:\Program Files\Realtek\Audio\HDA\FMAPP.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
(Synaptics) C:\Program Files\Synaptics\SynTP\SynLenovoGestureMgr.exe
(Microsoft Corporation) C:\Windows\System32\rundll32.exe
(Lenovo) C:\Program Files\Lenovo\Onekey Theater\OnekeyStudio.exe
(Lenovo (Beijing) Limited) C:\Program Files (x86)\Lenovo\Energy Management\Energy Management.exe
(Lenovo(beijing) Limited) C:\Program Files (x86)\Lenovo\Energy Management\utility.exe
(Valve Corporation) C:\Program Files (x86)\Steam\Steam.exe
(Dolby Laboratories Inc.) C:\Program Files (x86)\Dolby Home Theater v4\pcee4.exe
(Razer Inc.) C:\Program Files (x86)\Razer\Synapse\RzSynapse.exe
(LogMeIn Inc.) C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe
(CyberLink) C:\Program Files (x86)\Lenovo\YouCam\YCMMirage.exe
(Valve Corporation) C:\Program Files (x86)\Steam\bin\steamwebhelper.exe
(Valve Corporation) C:\Program Files (x86)\Common Files\Steam\SteamService.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
(Valve Corporation) C:\Program Files (x86)\Steam\bin\steamwebhelper.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
(TeamSpeak Systems GmbH) C:\Program Files\TeamSpeak 3 Client\ts3client_win64.exe
(forum.viry.cz) C:\Users\Blaze\Desktop\FRSTLauncher.exe
==================== Registry (Whitelisted) ===========================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [RtsFT] => C:\windows\RTFTrack.exe [6334096 2012-08-06] (Realtek semiconductor)
HKLM\...\Run: [RtHDVCpl] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [12937872 2012-07-27] (Realtek Semiconductor)
HKLM\...\Run: [RtHDVBg_Dolby] => C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [1214608 2012-07-10] (Realtek Semiconductor)
HKLM\...\Run: [SynLenovoGestureMgr] => C:\Program Files\Synaptics\SynTP\SynLenovoGestureMgr.exe [665400 2012-08-16] (Synaptics)
HKLM\...\Run: [BTMTrayAgent] => rundll32.exe "C:\Program Files (x86)\Intel\Bluetooth\btmshell.dll",TrayApp
HKLM\...\Run: [OnekeyStudio] => C:\Program Files\Lenovo\Onekey Theater\OnekeyStudio.exe [4196432 2012-08-10] (Lenovo)
HKLM\...\Run: [Energy Management] => C:\Program Files (x86)\Lenovo\Energy Management\Energy Management.exe [17080376 2015-01-23] (Lenovo (Beijing) Limited)
HKLM\...\Run: [EnergyUtility] => C:\Program Files (x86)\Lenovo\Energy Management\Utility.exe [191544 2015-01-23] (Lenovo(beijing) Limited)
HKLM\...\Run: [NvBackend] => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe [2396096 2016-03-30] (NVIDIA Corporation)
HKLM\...\Run: [ShadowPlay] => "C:\WINDOWS\system32\rundll32.exe" C:\WINDOWS\system32\nvspcap64.dll,ShadowPlayOnSystemStart
HKLM\...\Run: [SynTPEnh] => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2916152 2012-08-16] (Synaptics Incorporated)
HKLM-x32\...\Run: [IAStorIcon] => C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [277504 2012-07-09] (Intel Corporation)
HKLM-x32\...\Run: [Dolby Home Theater v4] => C:\Program Files (x86)\Dolby Home Theater v4\pcee4.exe [508656 2012-07-26] (Dolby Laboratories Inc.)
HKLM-x32\...\Run: [YouCam Mirage] => C:\Program Files (x86)\Lenovo\YouCam\YCMMirage.exe [136488 2012-07-27] (CyberLink)
HKLM-x32\...\Run: [YouCam Tray] => C:\Program Files (x86)\Lenovo\YouCam\YouCamTray.exe [167024 2012-07-27] (CyberLink Corp.)
HKLM-x32\...\Run: [] => [X]
HKLM-x32\...\Run: [Razer Synapse] => C:\Program Files (x86)\Razer\Synapse\RzSynapse.exe [592704 2015-09-29] (Razer Inc.)
HKLM-x32\...\Run: [LogMeIn Hamachi Ui] => C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe [5565448 2015-11-12] (LogMeIn Inc.)
HKU\S-1-5-21-2968257316-2402521077-608179223-1002\...\Run: [Steam] => C:\Program Files (x86)\Steam\steam.exe [3077712 2016-03-28] (Valve Corporation)
AppInit_DLLs: C:\PROGRA~2\NVIDIA~1\3DVISI~1\NVSTIN~1.DLL => No File
ShellIconOverlayIdentifiers: [SugarSyncBackedUp] -> {0C4A258A-3F3B-4FFF-80A7-9B3BEC139472} => C:\Program Files (x86)\SugarSync\SugarSyncShellExt_x64.dll [2012-05-14] (SugarSync, Inc.)
ShellIconOverlayIdentifiers: [SugarSyncPending] -> {62CCD8E3-9C21-41E1-B55E-1E26DFC68511} => C:\Program Files (x86)\SugarSync\SugarSyncShellExt_x64.dll [2012-05-14] (SugarSync, Inc.)
ShellIconOverlayIdentifiers: [SugarSyncRoot] -> {A759AFF6-5851-457D-A540-F4ECED148351} => C:\Program Files (x86)\SugarSync\SugarSyncShellExt_x64.dll [2012-05-14] (SugarSync, Inc.)
ShellIconOverlayIdentifiers: [SugarSyncShared] -> {1574C9EF-7D58-488F-B358-8B78C1538F51} => C:\Program Files (x86)\SugarSync\SugarSyncShellExt_x64.dll [2012-05-14] (SugarSync, Inc.)
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
Tcpip\Parameters: [DhcpNameServer] 192.168.1.1
Tcpip\..\Interfaces\{34F4C0CD-C847-4240-A11F-48469FB13C46}: [DhcpNameServer] 77.242.95.5 81.200.55.34
Tcpip\..\Interfaces\{599265BF-420E-41DF-860E-E9D872006E78}: [DhcpNameServer] 192.168.1.1
Internet Explorer:
==================
HKU\S-1-5-21-2968257316-2402521077-608179223-1002\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://lenovo13.msn.com
HKU\S-1-5-21-2968257316-2402521077-608179223-1002\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://lenovo13.msn.com
HKU\S-1-5-21-2968257316-2402521077-608179223-1002\Software\Microsoft\Internet Explorer\Main,Secondary Start Pages = hxxp://www.lenovo.com
HKU\S-1-5-21-2968257316-2402521077-608179223-1002\Software\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = hxxp://www.lenovo.com
SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-21-2968257316-2402521077-608179223-1002 -> {3676BAB6-88A8-4791-BB0D-29235C336008} URL =
FireFox:
========
FF ProfilePath: C:\Users\Blaze\AppData\Roaming\Mozilla\Firefox\Profiles\cwl9atgv.default-1428576093703
FF Homepage: hxxps://seznam.cz/
FF Plugin: @adobe.com/FlashPlayer -> C:\WINDOWS\system32\Macromed\Flash\NPSWF64_21_0_0_197.dll [2016-03-23] ()
FF Plugin: @esn/npbattlelog,version=2.7.1 -> C:\Program Files (x86)\Battlelog Web Plugins\2.7.1\npbattlelogx64.dll [2015-04-30] (EA Digital Illusions CE AB)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\WINDOWS\SysWOW64\Macromed\Flash\NPSWF32_21_0_0_197.dll [2016-03-23] ()
FF Plugin-x32: @esn/npbattlelog,version=2.7.1 -> C:\Program Files (x86)\Battlelog Web Plugins\2.7.1\npbattlelog.dll [2015-04-30] (EA Digital Illusions CE AB)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=2.1.42 -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll [2012-06-07] (Intel Corporation)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll [2012-06-07] (Intel Corporation)
FF Plugin-x32: @nvidia.com/3DVision -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll [2016-03-22] (NVIDIA Corporation)
FF Plugin-x32: @nvidia.com/3DVisionStreaming -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll [2016-03-22] (NVIDIA Corporation)
FF Plugin-x32: @raidcall.en/RCplugin -> C:\Users\Blaze\AppData\Roaming\raidcall\plugins\nprcplugin.dll [2014-05-27] (Raidcall)
FF Extension: Flash Video Downloader - YouTube HD Download [4K] - C:\Users\Blaze\AppData\Roaming\Mozilla\Firefox\Profiles\cwl9atgv.default-1428576093703\extensions\artur.dubovoy@gmail.com [2016-03-29]
FF Extension: Adblock Plus - C:\Users\Blaze\AppData\Roaming\Mozilla\Firefox\Profiles\cwl9atgv.default-1428576093703\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2016-02-24]
FF Extension: Default - C:\Program Files (x86)\Mozilla Firefox\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}.xpi [2016-03-19] [not signed]
FF HKLM-x32\...\Thunderbird\Extensions: [msktbird@mcafee.com] - C:\Program Files\McAfee\MSK => not found
==================== Services (Whitelisted) ========================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
S3 BEService; C:\Program Files (x86)\Common Files\BattlEye\BEService.exe [1345056 2016-02-11] ()
R2 ExpressCache; C:\Program Files\Diskeeper Corporation\ExpressCache\ExpressCache.exe [79664 2012-03-30] (Diskeeper Corporation)
R2 GfExperienceService; C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe [1163200 2016-03-30] (NVIDIA Corporation)
R2 IAStorDataMgrSvc; C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe [7168 2012-07-09] (Intel Corporation) [File not signed]
R2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [166720 2012-06-25] (Intel Corporation)
R2 LMIGuardianSvc; C:\Program Files (x86)\LogMeIn Hamachi\LMIGuardianSvc.exe [417552 2015-11-12] (LogMeIn, Inc.)
S2 MBAMService; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe [1133880 2015-06-18] (Malwarebytes Corporation)
S3 MyWiFiDHCPDNS; C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe [273136 2013-08-28] ()
R2 NvNetworkService; C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe [1879488 2016-03-30] (NVIDIA Corporation)
R3 NvStreamNetworkSvc; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamNetworkService.exe [3632576 2016-03-30] (NVIDIA Corporation)
R2 NvStreamSvc; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamService.exe [2521024 2016-03-30] (NVIDIA Corporation)
S3 Origin Client Service; C:\Program Files (x86)\Origin\OriginClientService.exe [2119688 2016-03-30] (Electronic Arts)
R2 PnkBstrA; C:\WINDOWS\system32\PnkBstrA.exe [76152 2016-03-25] ()
R2 PnkBstrA; C:\WINDOWS\SysWOW64\PnkBstrA.exe [76888 2016-03-25] ()
R2 Razer Game Scanner Service; C:\Program Files (x86)\Razer\Razer Services\GSS\GameScannerService.exe [187048 2015-06-23] ()
R3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [366520 2015-04-16] (Microsoft Corporation)
R2 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [23792 2015-04-16] (Microsoft Corporation)
R2 ZeroConfigService; C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe [3378416 2013-08-28] (Intel® Corporation)
===================== Drivers (Whitelisted) ==========================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
S0 ebdrv; C:\Windows\System32\drivers\evbda.sys [3357024 2013-08-22] (Broadcom Corporation)
R1 excfs; C:\Windows\System32\DRIVERS\excfs.sys [23344 2012-03-30] (Diskeeper Corporation)
R0 excsd; C:\Windows\System32\DRIVERS\excsd.sys [95024 2012-03-30] (Diskeeper Corporation)
R3 Hamachi; C:\Windows\system32\DRIVERS\Hamdrv.sys [45680 2015-11-12] (LogMeIn Inc.)
R3 MBAMProtector; C:\WINDOWS\system32\drivers\mbam.sys [25816 2015-06-18] (Malwarebytes Corporation)
S3 MBAMWebAccessControl; C:\WINDOWS\system32\drivers\mwac.sys [64216 2015-06-18] (Malwarebytes Corporation)
R3 NETwNe64; C:\Windows\system32\DRIVERS\Netwew00.sys [3345376 2013-10-08] (Intel Corporation)
R3 NvStreamKms; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys [26560 2016-03-30] (NVIDIA Corporation)
R3 nvvad_WaveExtensible; C:\Windows\system32\drivers\nvvad64v.sys [56384 2016-03-21] (NVIDIA Corporation)
R3 rtsuvc; C:\Windows\system32\DRIVERS\rtsuvc.sys [8226832 2012-08-06] (Realtek Semiconductor Corp.)
R2 rzpmgrk; C:\WINDOWS\system32\drivers\rzpmgrk.sys [37184 2015-06-12] (Razer, Inc.)
R2 rzpnk; C:\WINDOWS\system32\drivers\rzpnk.sys [129472 2015-06-27] (Razer, Inc.)
R3 SmbDrvI; C:\Windows\system32\DRIVERS\Smb_driver_Intel.sys [43832 2012-08-16] (Synaptics Incorporated)
S0 WdBoot; C:\Windows\System32\drivers\WdBoot.sys [44024 2015-04-16] (Microsoft Corporation)
R0 WdFilter; C:\Windows\System32\drivers\WdFilter.sys [264000 2015-04-16] (Microsoft Corporation)
R3 WdNisDrv; C:\Windows\System32\Drivers\WdNisDrv.sys [114496 2015-04-16] (Microsoft Corporation)
S3 wsvd; C:\Windows\system32\DRIVERS\wsvd.sys [102376 2012-06-14] ("CyberLink)
==================== NetSvcs (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
==================== One Month Created files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2016-03-31 20:21 - 2016-03-31 20:22 - 00016294 _____ C:\Users\Blaze\Desktop\FRST.txt
2016-03-31 20:21 - 2016-03-31 20:21 - 00000000 ____D C:\FRST
2016-03-31 20:17 - 2016-03-31 20:17 - 00112640 _____ (forum.viry.cz) C:\Users\Blaze\Desktop\FRSTLauncher.exe
2016-03-31 20:13 - 2016-03-31 20:13 - 02374144 _____ (Farbar) C:\Users\Blaze\Desktop\FRST64.exe
2016-03-31 02:55 - 2016-03-31 02:55 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Vulkan
2016-03-31 02:55 - 2016-03-22 04:10 - 00112184 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvStreaming.exe
2016-03-31 02:54 - 2016-03-31 02:54 - 00000000 ____D C:\WINDOWS\LastGood
2016-03-31 02:52 - 2016-03-22 06:12 - 42923576 _____ C:\WINDOWS\system32\nvcompiler.dll
2016-03-31 02:52 - 2016-03-22 06:12 - 37567424 _____ C:\WINDOWS\SysWOW64\nvcompiler.dll
2016-03-31 02:52 - 2016-03-22 06:12 - 31555008 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvoglv64.dll
2016-03-31 02:52 - 2016-03-22 06:12 - 25321408 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvoglv32.dll
2016-03-31 02:52 - 2016-03-22 06:12 - 21355248 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvopencl.dll
2016-03-31 02:52 - 2016-03-22 06:12 - 20897416 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvcuda.dll
2016-03-31 02:52 - 2016-03-22 06:12 - 19004040 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvwgf2umx.dll
2016-03-31 02:52 - 2016-03-22 06:12 - 17748712 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvopencl.dll
2016-03-31 02:52 - 2016-03-22 06:12 - 17342392 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvcuda.dll
2016-03-31 02:52 - 2016-03-22 06:12 - 17248408 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvd3dumx.dll
2016-03-31 02:52 - 2016-03-22 06:12 - 16446032 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvwgf2um.dll
2016-03-31 02:52 - 2016-03-22 06:12 - 14128840 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvd3dum.dll
2016-03-31 02:52 - 2016-03-22 06:12 - 12567608 _____ (NVIDIA Corporation) C:\WINDOWS\system32\Drivers\nvlddmkm.sys
2016-03-31 02:52 - 2016-03-22 06:12 - 10550736 _____ C:\WINDOWS\system32\nvptxJitCompiler.dll
2016-03-31 02:52 - 2016-03-22 06:12 - 08659472 _____ C:\WINDOWS\SysWOW64\nvptxJitCompiler.dll
2016-03-31 02:52 - 2016-03-22 06:12 - 03714472 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvapi64.dll
2016-03-31 02:52 - 2016-03-22 06:12 - 03286992 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvapi.dll
2016-03-31 02:52 - 2016-03-22 06:12 - 03235896 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvcuvid.dll
2016-03-31 02:52 - 2016-03-22 06:12 - 02809280 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvcuvid.dll
2016-03-31 02:52 - 2016-03-22 06:12 - 01924152 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvdispco6436472.dll
2016-03-31 02:52 - 2016-03-22 06:12 - 01573432 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvdispgenco6436472.dll
2016-03-31 02:52 - 2016-03-22 06:12 - 00959544 _____ (NVIDIA Corporation) C:\WINDOWS\system32\NvFBC64.dll
2016-03-31 02:52 - 2016-03-22 06:12 - 00889400 _____ (NVIDIA Corporation) C:\WINDOWS\system32\NvIFR64.dll
2016-03-31 02:52 - 2016-03-22 06:12 - 00753208 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\NvFBC.dll
2016-03-31 02:52 - 2016-03-22 06:12 - 00695864 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\NvIFR.dll
2016-03-31 02:52 - 2016-03-22 06:12 - 00678520 _____ C:\WINDOWS\system32\nvfatbinaryLoader.dll
2016-03-31 02:52 - 2016-03-22 06:12 - 00571912 _____ C:\WINDOWS\SysWOW64\nvfatbinaryLoader.dll
2016-03-31 02:52 - 2016-03-22 06:12 - 00501896 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvEncodeAPI64.dll
2016-03-31 02:52 - 2016-03-22 06:12 - 00425016 _____ (NVIDIA Corporation) C:\WINDOWS\system32\NvIFROpenGL.dll
2016-03-31 02:52 - 2016-03-22 06:12 - 00423080 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvEncodeAPI.dll
2016-03-31 02:52 - 2016-03-22 06:12 - 00377792 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\NvIFROpenGL.dll
2016-03-31 02:52 - 2016-03-22 06:12 - 00000139 _____ C:\WINDOWS\SysWOW64\nv-vk32.json
2016-03-31 02:52 - 2016-03-22 06:12 - 00000139 _____ C:\WINDOWS\system32\nv-vk64.json
2016-03-31 02:33 - 2016-03-31 02:33 - 00000000 ____D C:\WINDOWS\LastGood.Tmp
2016-03-31 02:33 - 2016-03-21 22:01 - 00109632 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvaudcap64v.dll
2016-03-31 02:33 - 2016-03-21 22:01 - 00100416 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvaudcap32v.dll
2016-03-31 02:33 - 2016-03-21 22:01 - 00056384 _____ (NVIDIA Corporation) C:\WINDOWS\system32\Drivers\nvvad64v.sys
2016-03-31 01:35 - 2016-03-31 02:32 - 00000000 ____D C:\ProgramData\Malwarebytes' Anti-Malware (portable)
2016-03-31 01:33 - 2016-03-31 02:32 - 00000000 ____D C:\Users\Blaze\Desktop\mbar
2016-03-31 01:32 - 2016-03-31 01:32 - 16563352 _____ (Malwarebytes Corp.) C:\Users\Blaze\Desktop\mbar-1.09.3.1001.exe
2016-03-31 01:03 - 2016-03-31 01:03 - 03102720 _____ C:\Users\Blaze\Downloads\adwcleaner_5.108.exe
2016-03-30 22:29 - 2016-03-30 22:29 - 00000000 ____D C:\rsit
2016-03-29 00:13 - 2016-03-29 00:37 - 411326664 _____ C:\Users\Blaze\Downloads\loves01e10.mp4
2016-03-28 20:39 - 2016-03-28 20:54 - 228736064 _____ C:\Users\Blaze\Downloads\loves01e09.mp4
2016-03-28 08:45 - 2016-03-28 08:48 - 221898939 _____ C:\Users\Blaze\Downloads\loves01e07.mp4
2016-03-28 07:40 - 2016-03-28 07:44 - 290769501 _____ C:\Users\Blaze\Downloads\loves01e06.mp4
2016-03-28 06:34 - 2016-03-28 06:37 - 261010205 _____ C:\Users\Blaze\Downloads\loves01e05.mp4
2016-03-28 05:35 - 2016-03-28 05:38 - 286555922 _____ C:\Users\Blaze\Downloads\loves01e04.mp4
2016-03-28 05:00 - 2016-03-28 05:03 - 259122073 _____ C:\Users\Blaze\Downloads\loves01e03.mp4
2016-03-25 18:28 - 2016-03-25 18:28 - 00076152 _____ C:\WINDOWS\system32\PnkBstrA.exe
2016-03-25 10:36 - 2016-03-25 10:41 - 00000000 ____D C:\Users\Blaze\Documents\Battlefield 4
2016-03-25 10:36 - 2016-03-25 10:36 - 00000000 ____D C:\Users\Blaze\AppData\Local\ESN
2016-03-25 10:35 - 2016-03-25 10:35 - 01640768 _____ C:\Users\Blaze\Downloads\battlelog-web-plugins_2.7.1_162(1).exe
2016-03-25 09:50 - 2016-03-25 09:50 - 00001263 _____ C:\Users\Public\Desktop\Battlefield 4.lnk
2016-03-25 09:50 - 2016-03-25 09:50 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Battlefield 4
2016-03-23 16:49 - 2016-03-31 02:55 - 00000000 ____D C:\Program Files (x86)\VulkanRT
2016-03-23 16:49 - 2016-03-23 16:49 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Vulkan 1.0.3.0
2016-03-23 16:49 - 2016-03-16 23:30 - 00128792 _____ C:\WINDOWS\SysWOW64\vulkan-1.dll
2016-03-23 16:49 - 2016-03-16 23:29 - 00127768 _____ C:\WINDOWS\system32\vulkan-1.dll
2016-03-23 16:49 - 2016-03-16 23:29 - 00041752 _____ C:\WINDOWS\SysWOW64\vulkaninfo.exe
2016-03-23 16:49 - 2016-03-16 23:28 - 00045848 _____ C:\WINDOWS\system32\vulkaninfo.exe
2016-03-23 16:46 - 2016-03-08 12:07 - 01924152 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvdispco6436451.dll
2016-03-23 16:46 - 2016-03-08 12:07 - 01571776 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvdispgenco6436451.dll
2016-03-23 15:40 - 2016-03-23 15:40 - 00000000 ____D C:\Users\Blaze\AppData\Local\Victory
2016-03-23 15:40 - 2016-03-23 15:40 - 00000000 ____D C:\Users\Blaze\AppData\Local\UnrealEngine
2016-03-23 15:40 - 2015-08-22 15:42 - 00901264 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ucrtbase.dll
2016-03-23 15:40 - 2015-08-22 15:42 - 00066400 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\api-ms-win-crt-private-l1-1-0.dll
2016-03-23 15:40 - 2015-08-22 15:42 - 00022368 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\api-ms-win-crt-math-l1-1-0.dll
2016-03-23 15:40 - 2015-08-22 15:42 - 00019808 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\api-ms-win-crt-multibyte-l1-1-0.dll
2016-03-23 15:40 - 2015-08-22 15:42 - 00017760 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\api-ms-win-crt-string-l1-1-0.dll
2016-03-23 15:40 - 2015-08-22 15:42 - 00017760 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\api-ms-win-crt-stdio-l1-1-0.dll
2016-03-23 15:40 - 2015-08-22 15:42 - 00016224 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\api-ms-win-crt-runtime-l1-1-0.dll
2016-03-23 15:40 - 2015-08-22 15:42 - 00015712 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\api-ms-win-crt-convert-l1-1-0.dll
2016-03-23 15:40 - 2015-08-22 15:42 - 00014176 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\api-ms-win-crt-time-l1-1-0.dll
2016-03-23 15:40 - 2015-08-22 15:42 - 00013664 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\api-ms-win-crt-filesystem-l1-1-0.dll
2016-03-23 15:40 - 2015-08-22 15:42 - 00012640 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\api-ms-win-crt-process-l1-1-0.dll
2016-03-23 15:40 - 2015-08-22 15:42 - 00012640 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\api-ms-win-crt-heap-l1-1-0.dll
2016-03-23 15:40 - 2015-08-22 15:42 - 00012640 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\api-ms-win-crt-conio-l1-1-0.dll
2016-03-23 15:40 - 2015-08-22 15:42 - 00012128 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\api-ms-win-crt-utility-l1-1-0.dll
2016-03-23 15:40 - 2015-08-22 15:42 - 00012128 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\api-ms-win-crt-locale-l1-1-0.dll
2016-03-23 15:40 - 2015-08-22 15:42 - 00012128 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\api-ms-win-crt-environment-l1-1-0.dll
2016-03-23 15:40 - 2015-08-22 15:35 - 00984448 _____ (Microsoft Corporation) C:\WINDOWS\system32\ucrtbase.dll
2016-03-23 15:40 - 2015-08-22 15:35 - 00063840 _____ (Microsoft Corporation) C:\WINDOWS\system32\api-ms-win-crt-private-l1-1-0.dll
2016-03-23 15:40 - 2015-08-22 15:35 - 00020832 _____ (Microsoft Corporation) C:\WINDOWS\system32\api-ms-win-crt-math-l1-1-0.dll
2016-03-23 15:40 - 2015-08-22 15:35 - 00019808 _____ (Microsoft Corporation) C:\WINDOWS\system32\api-ms-win-crt-multibyte-l1-1-0.dll
2016-03-23 15:40 - 2015-08-22 15:35 - 00017760 _____ (Microsoft Corporation) C:\WINDOWS\system32\api-ms-win-crt-string-l1-1-0.dll
2016-03-23 15:40 - 2015-08-22 15:35 - 00017760 _____ (Microsoft Corporation) C:\WINDOWS\system32\api-ms-win-crt-stdio-l1-1-0.dll
2016-03-23 15:40 - 2015-08-22 15:35 - 00016224 _____ (Microsoft Corporation) C:\WINDOWS\system32\api-ms-win-crt-runtime-l1-1-0.dll
2016-03-23 15:40 - 2015-08-22 15:35 - 00015712 _____ (Microsoft Corporation) C:\WINDOWS\system32\api-ms-win-crt-convert-l1-1-0.dll
2016-03-23 15:40 - 2015-08-22 15:35 - 00014176 _____ (Microsoft Corporation) C:\WINDOWS\system32\api-ms-win-crt-time-l1-1-0.dll
2016-03-23 15:40 - 2015-08-22 15:35 - 00013664 _____ (Microsoft Corporation) C:\WINDOWS\system32\api-ms-win-crt-filesystem-l1-1-0.dll
2016-03-23 15:40 - 2015-08-22 15:35 - 00012640 _____ (Microsoft Corporation) C:\WINDOWS\system32\api-ms-win-crt-process-l1-1-0.dll
2016-03-23 15:40 - 2015-08-22 15:35 - 00012640 _____ (Microsoft Corporation) C:\WINDOWS\system32\api-ms-win-crt-heap-l1-1-0.dll
2016-03-23 15:40 - 2015-08-22 15:35 - 00012640 _____ (Microsoft Corporation) C:\WINDOWS\system32\api-ms-win-crt-conio-l1-1-0.dll
2016-03-23 15:40 - 2015-08-22 15:35 - 00012128 _____ (Microsoft Corporation) C:\WINDOWS\system32\api-ms-win-crt-utility-l1-1-0.dll
2016-03-23 15:40 - 2015-08-22 15:35 - 00012128 _____ (Microsoft Corporation) C:\WINDOWS\system32\api-ms-win-crt-locale-l1-1-0.dll
2016-03-23 15:40 - 2015-08-22 15:35 - 00012128 _____ (Microsoft Corporation) C:\WINDOWS\system32\api-ms-win-crt-environment-l1-1-0.dll
2016-03-19 22:56 - 2016-03-20 16:31 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox
2016-03-16 23:30 - 2016-03-16 23:30 - 00128792 _____ C:\WINDOWS\SysWOW64\vulkan-1-1-0-5-1.dll
2016-03-16 23:29 - 2016-03-16 23:29 - 00127768 _____ C:\WINDOWS\system32\vulkan-1-1-0-5-1.dll
2016-03-16 23:29 - 2016-03-16 23:29 - 00041752 _____ C:\WINDOWS\SysWOW64\vulkaninfo-1-1-0-5-1.exe
2016-03-16 23:28 - 2016-03-16 23:28 - 00045848 _____ C:\WINDOWS\system32\vulkaninfo-1-1-0-5-1.exe
2016-03-13 21:22 - 2016-03-31 01:07 - 00000000 ____D C:\Program Files (x86)\Battlelog Web Plugins
2016-03-13 21:22 - 2016-03-13 21:22 - 01640768 _____ C:\Users\Blaze\Downloads\battlelog-web-plugins_2.7.1_162.exe
2016-03-13 21:19 - 2016-03-13 21:23 - 00000000 ____D C:\Users\Blaze\Documents\Battlefield 3
2016-03-13 20:44 - 2016-03-13 20:44 - 00001197 _____ C:\Users\Public\Desktop\Battlefield 3.lnk
2016-03-13 20:44 - 2016-03-13 20:44 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Battlefield 3
2016-03-13 20:04 - 2016-03-25 09:06 - 00000000 ____D C:\Program Files (x86)\Origin Games
2016-03-13 20:01 - 2016-03-13 21:19 - 00000000 ____D C:\Users\Blaze\AppData\Local\Origin
2016-03-13 20:00 - 2016-03-13 20:00 - 00001002 _____ C:\Users\Public\Desktop\Origin.lnk
2016-03-13 20:00 - 2016-03-13 20:00 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Origin
2016-03-13 19:58 - 2016-03-30 00:15 - 00000000 ____D C:\Program Files (x86)\Origin
2016-03-13 19:57 - 2016-03-13 19:58 - 31334856 _____ (Electronic Arts, Inc.) C:\Users\Blaze\Downloads\OriginThinSetup(1).exe
2016-03-13 16:09 - 2016-03-13 16:09 - 00001900 _____ C:\Users\Blaze\Downloads\SWAG.Stratis.rar
2016-03-02 02:44 - 2016-02-24 01:58 - 01922496 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvdispco6436200.dll
2016-03-02 02:44 - 2016-02-24 01:58 - 01571776 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvdispgenco6436200.dll
==================== One Month Modified files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2016-03-31 20:19 - 2015-04-09 11:10 - 00000000 ____D C:\Users\Blaze\AppData\Roaming\TS3Client
2016-03-31 20:00 - 2015-07-28 05:01 - 00003966 _____ C:\WINDOWS\System32\Tasks\User_Feed_Synchronization-{5075C313-9A99-4915-B33E-BFE454DDEDD3}
2016-03-31 19:59 - 2015-12-17 15:24 - 00000000 ____D C:\Users\Blaze\AppData\Local\LogMeIn Hamachi
2016-03-31 19:59 - 2015-04-09 19:46 - 00000000 ____D C:\Program Files (x86)\Steam
2016-03-31 08:55 - 2015-05-14 17:54 - 00000914 _____ C:\WINDOWS\Tasks\Adobe Flash Player Updater.job
2016-03-31 08:09 - 2015-04-09 19:30 - 00003598 _____ C:\WINDOWS\System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-2968257316-2402521077-608179223-1002
2016-03-31 03:27 - 2015-04-23 11:29 - 00000080 _____ C:\Users\Blaze\AppData\Local剜捯獫慴慇敭屳呇⁁屖湥楴汴浥湥湩潦
2016-03-31 03:07 - 2015-01-23 18:35 - 00000000 ____D C:\ProgramData\NVIDIA
2016-03-31 03:07 - 2013-08-22 16:45 - 00000006 ____H C:\WINDOWS\Tasks\SA.DAT
2016-03-31 03:01 - 2015-12-28 22:28 - 00000000 ____D C:\Users\Blaze\AppData\Local\CrashDumps
2016-03-31 02:55 - 2015-04-16 00:01 - 00000000 ____D C:\ProgramData\NVIDIA Corporation
2016-03-31 02:55 - 2013-08-22 15:36 - 00000000 ____D C:\WINDOWS\Inf
2016-03-31 02:54 - 2015-04-16 00:01 - 00000000 ____D C:\Program Files\NVIDIA Corporation
2016-03-31 02:44 - 2013-08-22 15:25 - 00262144 ___SH C:\WINDOWS\system32\config\BBI
2016-03-31 01:35 - 2015-07-22 23:38 - 00192216 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\MBAMSwissArmy.sys
2016-03-31 01:34 - 2015-07-22 23:38 - 00109272 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\mbamchameleon.sys
2016-03-31 01:14 - 2015-07-15 11:09 - 00000000 ____D C:\Program Files (x86)\Bloody5
2016-03-31 01:14 - 2014-11-21 06:53 - 01749406 _____ C:\WINDOWS\system32\PerfStringBackup.INI
2016-03-31 01:14 - 2014-11-21 06:10 - 00740962 _____ C:\WINDOWS\system32\perfh005.dat
2016-03-31 01:14 - 2014-11-21 06:10 - 00152146 _____ C:\WINDOWS\system32\perfc005.dat
2016-03-31 01:06 - 2015-06-06 20:07 - 00000000 ____D C:\AdwCleaner
2016-03-31 01:05 - 2015-04-23 08:12 - 00000000 ____D C:\ProgramData\Origin
2016-03-30 23:57 - 2015-04-23 08:50 - 00226168 _____ C:\WINDOWS\SysWOW64\PnkBstrB.exe
2016-03-30 23:51 - 2015-04-23 08:50 - 00226168 _____ C:\WINDOWS\SysWOW64\PnkBstrB.ex0
2016-03-30 22:29 - 2015-04-10 11:00 - 00000000 ____D C:\Program Files\trend micro
2016-03-30 06:07 - 2015-04-09 12:13 - 00000000 ____D C:\Users\Blaze\AppData\Local\ArmA 2 OA
2016-03-30 05:43 - 2015-04-23 11:31 - 00001754 _____ C:\Users\Blaze\Desktop\66M3-QGTZ-YJVP-VHFK.txt
2016-03-30 03:06 - 2015-04-10 13:39 - 01373680 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvspcap.dll
2016-03-30 03:06 - 2015-04-10 13:39 - 01316000 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvspbridge.dll
2016-03-30 03:05 - 2015-11-21 16:19 - 00112216 _____ C:\WINDOWS\system32\NvRtmpStreamer64.dll
2016-03-30 03:05 - 2015-04-10 13:39 - 01767248 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvspcap64.dll
2016-03-30 03:05 - 2015-04-10 13:39 - 01756424 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvspbridge64.dll
2016-03-29 19:03 - 2015-05-10 14:56 - 00000000 ____D C:\Users\Blaze\AppData\Local\Arma 3
2016-03-29 05:43 - 2015-04-09 11:13 - 00000000 ____D C:\Users\Blaze\AppData\Roaming\Skype
2016-03-29 05:35 - 2015-04-09 12:48 - 00000000 ____D C:\Users\Blaze\AppData\Local\Battle.net
2016-03-29 05:09 - 2015-04-09 13:34 - 00000000 ____D C:\Program Files (x86)\World of Warcraft
2016-03-29 05:06 - 2015-04-09 12:47 - 00000000 ____D C:\Program Files (x86)\Battle.net
2016-03-29 00:41 - 2015-04-09 13:53 - 00000000 ____D C:\KMPlayer
2016-03-26 19:06 - 2015-04-23 11:28 - 00000000 ____D C:\Program Files\Rockstar Games
2016-03-26 19:06 - 2015-04-23 11:28 - 00000000 ____D C:\Program Files (x86)\Rockstar Games
2016-03-25 10:40 - 2015-04-23 20:04 - 00000000 ____D C:\Users\Blaze\AppData\Local\PunkBuster
2016-03-25 09:50 - 2015-04-23 08:50 - 00076888 _____ C:\WINDOWS\SysWOW64\PnkBstrA.exe
2016-03-25 09:50 - 2015-04-09 10:53 - 00000000 ____D C:\ProgramData\Package Cache
2016-03-25 03:09 - 2015-04-23 20:04 - 00348360 _____ C:\WINDOWS\SysWOW64\PnkBstrB.xtr
2016-03-23 23:55 - 2015-04-09 13:45 - 00003802 _____ C:\WINDOWS\System32\Tasks\Adobe Flash Player Updater
2016-03-23 15:40 - 2012-07-26 09:59 - 00000000 ____D C:\WINDOWS\CbsTemp
2016-03-23 02:48 - 2016-02-22 04:35 - 00000000 ____D C:\Program Files (x86)\A3Launcher
2016-03-22 06:12 - 2015-04-14 00:04 - 00037091 _____ C:\WINDOWS\system32\nvinfo.pb
2016-03-22 04:25 - 2015-12-27 07:29 - 00532536 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nv3dappshext.dll
2016-03-22 04:25 - 2015-12-27 07:29 - 00081856 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nv3dappshextr.dll
2016-03-22 04:25 - 2015-04-16 00:02 - 06369728 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvcpl.dll
2016-03-22 04:25 - 2015-04-16 00:02 - 02993088 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvsvc64.dll
2016-03-22 04:25 - 2015-04-16 00:02 - 02561472 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvsvcr.dll
2016-03-22 04:25 - 2015-04-16 00:02 - 01264064 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvvsvc.exe
2016-03-22 04:25 - 2015-04-16 00:02 - 00393784 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvmctray.dll
2016-03-22 04:25 - 2015-04-16 00:02 - 00123960 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\oemdspif.dll
2016-03-22 04:25 - 2015-04-16 00:02 - 00069568 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvshext.dll
2016-03-21 04:52 - 2015-04-16 00:12 - 00000000 ____D C:\Users\Blaze
2016-03-20 16:31 - 2015-04-09 19:44 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2016-03-18 20:10 - 2015-04-16 00:02 - 06253721 _____ C:\WINDOWS\system32\nvcoproc.bin
2016-03-13 22:50 - 2013-08-22 17:36 - 00000000 ___HD C:\Program Files\WindowsApps
2016-03-13 22:50 - 2013-08-22 17:36 - 00000000 ____D C:\WINDOWS\AppReadiness
2016-03-11 16:46 - 2015-05-10 14:56 - 00000000 ____D C:\Users\Blaze\Documents\Arma 3
2016-03-09 23:26 - 2015-04-09 11:12 - 00000000 ____D C:\ProgramData\Skype
2016-03-03 01:44 - 2015-04-09 12:48 - 00000000 ____D C:\Users\Blaze\AppData\Roaming\Battle.net
==================== Files in the root of some directories =======
2015-01-23 18:42 - 2015-01-23 18:42 - 0000000 ____H () C:\ProgramData\DP45977C.lfl
Some files in TEMP:
====================
C:\Users\Blaze\AppData\Local\Temp\libeay32.dll
C:\Users\Blaze\AppData\Local\Temp\mpam-d29af102.exe
C:\Users\Blaze\AppData\Local\Temp\msvcr120.dll
C:\Users\Blaze\AppData\Local\Temp\nvSCPAPI.dll
C:\Users\Blaze\AppData\Local\Temp\nvSCPAPI64.dll
C:\Users\Blaze\AppData\Local\Temp\nvSCPAPISvr.exe
C:\Users\Blaze\AppData\Local\Temp\nvStInst.exe
C:\Users\Blaze\AppData\Local\Temp\Razor_Latest.exe
C:\Users\Blaze\AppData\Local\Temp\SkypeSetup.exe
C:\Users\Blaze\AppData\Local\Temp\sonarinst.exe
C:\Users\Blaze\AppData\Local\Temp\sqlite3.dll
C:\Users\Blaze\AppData\Local\Temp\_unps.exe
==================== Bamital & volsnap =================
(There is no automatic fix for files that do not pass verification.)
C:\WINDOWS\system32\winlogon.exe => File is digitally signed
C:\WINDOWS\system32\wininit.exe => File is digitally signed
C:\WINDOWS\explorer.exe => File is digitally signed
C:\WINDOWS\SysWOW64\explorer.exe => File is digitally signed
C:\WINDOWS\system32\svchost.exe => File is digitally signed
C:\WINDOWS\SysWOW64\svchost.exe => File is digitally signed
C:\WINDOWS\system32\services.exe => File is digitally signed
C:\WINDOWS\system32\User32.dll => File is digitally signed
C:\WINDOWS\SysWOW64\User32.dll => File is digitally signed
C:\WINDOWS\system32\userinit.exe => File is digitally signed
C:\WINDOWS\SysWOW64\userinit.exe => File is digitally signed
C:\WINDOWS\system32\rpcss.dll => File is digitally signed
C:\WINDOWS\system32\dnsapi.dll => File is digitally signed
C:\WINDOWS\SysWOW64\dnsapi.dll => File is digitally signed
C:\WINDOWS\system32\Drivers\volsnap.sys => File is digitally signed
===***===***===***=== Extract of Additional scan result of Farbar Recovery Scan Tool ===***===***===***===
==================== Drive and Memory info ===================
==================== MBR and Partition Table ==================
==================== Scheduled Tasks (whitelisted) ==================
(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)
Task: C:\WINDOWS\Tasks\Adobe Flash Player Updater.job => C:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\WINDOWS\Tasks\Synaptics TouchPad Enhancements.job => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
==================== Alternate Data Streams (whitelisted) ==================
==================== Security Center ==================
AV: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
===***===***===***=== Supplementary Scan createdy by FRSTLauncher ===***===***===***===
Posledni aktualizace FRSTLauncheru: 25_11_2013 (01)
Posledni aktualizace Modifikacniho skriptu: 30_09_2013 (01)
***** Velikost "Plochy" *****
Velikost slozky "C:\Users\Blaze\Desktop" je 70 MB.
***** Startup Programs *****
***** Firewall rules *****
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
EnableFirewall REG_DWORD 0x1
DisableNotifications REG_DWORD 0x0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
EnableFirewall REG_DWORD 0x1
DisableNotifications REG_DWORD 0x0
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
***** System Restore *****
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"Generalize_DisableSR"=dword:00000000
==================== End Of Log ==============================
- Přílohy
-
- Addition.rar
- (11.89 KiB) Staženo 41 x
Re: Zasekany notebook
- Do Poznamkoveho bloku (Start -> spustit -> notepad) zkopirujte obsah bileho pole
- ulozte na plochu jako fixlist (Typ souboru: Textovy dokument)
- znovu spustte FRST a kliknete na Fix
- po restartu bude na plose ulozen fixlog, jehoz obsah vlozte do pristi odpovedi
Kód: Vybrat vše
Start CreateRestorePoint: CloseProcesses: Folder: C:\Users\Blaze\AppData\Local\CrashDumps File: C:\Program Files (x86)\Common Files\BattlEye\BEService.exe HKLM\...\Run: [NvBackend] => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe [2396096 2016-03-30] (NVIDIA Corporation) HKLM-x32\...\Run: [] => [X] AppInit_DLLs: C:\PROGRA~2\NVIDIA~1\3DVISI~1\NVSTIN~1.DLL => No File SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKU\S-1-5-21-2968257316-2402521077-608179223-1002 -> {3676BAB6-88A8-4791-BB0D-29235C336008} URL = 2016-03-31 01:35 - 2016-03-31 02:32 - 00000000 ____D C:\ProgramData\Malwarebytes' Anti-Malware (portable) 2016-03-31 01:33 - 2016-03-31 02:32 - 00000000 ____D C:\Users\Blaze\Desktop\mbar 2016-03-31 01:32 - 2016-03-31 01:32 - 16563352 _____ (Malwarebytes Corp.) C:\Users\Blaze\Desktop\mbar-1.09.3.1001.exe 2016-03-31 01:03 - 2016-03-31 01:03 - 03102720 _____ C:\Users\Blaze\Downloads\adwcleaner_5.108.exe 2016-03-30 22:29 - 2016-03-30 22:29 - 00000000 ____D C:\rsit 2016-03-31 01:06 - 2015-06-06 20:07 - 00000000 ____D C:\AdwCleaner 2016-03-30 22:29 - 2015-04-10 11:00 - 00000000 ____D C:\Program Files\trend micro Task: {6D3A0717-BB62-4C48-96E0-FB2F10DCF092} - System32\Tasks\{C46BF320-C4B0-46EE-A6B9-83DCE8692288} => pcalua.exe -a C:\Users\Blaze\AppData\Roaming\ICQM\icqsetup.exe -c -uninstallcu EmptyTemp: End
Pokud je cokoliv nejasného, ihned se ptej.
V případě spokojenosti prosím podpořte forum.
Pro dotazy, které se nehodí na forum, je možné využít altrokzavináčforum.viry.cz
Máš-li chuť pomáhat návštěvníkům tohoto fora, přihlas se do naší školičky.
V případě spokojenosti prosím podpořte forum.
Pro dotazy, které se nehodí na forum, je možné využít altrokzavináčforum.viry.cz
Máš-li chuť pomáhat návštěvníkům tohoto fora, přihlas se do naší školičky.
Re: Zasekany notebook
Dobry den. Posilam FixLog. Zatim tezko rict jestli se notebook chova lepe, to se ukaze casem.
Fix result of Farbar Recovery Scan Tool (x64) Version:05-03-2016 01
Ran by Blaze (2016-04-01 00:59:14) Run:1
Running from C:\Users\Blaze\Desktop
Loaded Profiles: Blaze (Available Profiles: Blaze)
Boot Mode: Normal
==============================================
fixlist content:
*****************
Start
CreateRestorePoint:
CloseProcesses:
Folder: C:\Users\Blaze\AppData\Local\CrashDumps
File: C:\Program Files (x86)\Common Files\BattlEye\BEService.exe
HKLM\...\Run: [NvBackend] => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe [2396096 2016-03-30] (NVIDIA Corporation)
HKLM-x32\...\Run: [] => [X]
AppInit_DLLs: C:\PROGRA~2\NVIDIA~1\3DVISI~1\NVSTIN~1.DLL => No File
SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-21-2968257316-2402521077-608179223-1002 -> {3676BAB6-88A8-4791-BB0D-29235C336008} URL =
2016-03-31 01:35 - 2016-03-31 02:32 - 00000000 ____D C:\ProgramData\Malwarebytes' Anti-Malware (portable)
2016-03-31 01:33 - 2016-03-31 02:32 - 00000000 ____D C:\Users\Blaze\Desktop\mbar
2016-03-31 01:32 - 2016-03-31 01:32 - 16563352 _____ (Malwarebytes Corp.) C:\Users\Blaze\Desktop\mbar-1.09.3.1001.exe
2016-03-31 01:03 - 2016-03-31 01:03 - 03102720 _____ C:\Users\Blaze\Downloads\adwcleaner_5.108.exe
2016-03-30 22:29 - 2016-03-30 22:29 - 00000000 ____D C:\rsit
2016-03-31 01:06 - 2015-06-06 20:07 - 00000000 ____D C:\AdwCleaner
2016-03-30 22:29 - 2015-04-10 11:00 - 00000000 ____D C:\Program Files\trend micro
Task: {6D3A0717-BB62-4C48-96E0-FB2F10DCF092} - System32\Tasks\{C46BF320-C4B0-46EE-A6B9-83DCE8692288} => pcalua.exe -a C:\Users\Blaze\AppData\Roaming\ICQM\icqsetup.exe -c -uninstallcu
EmptyTemp:
End
*****************
Restore point was successfully created.
Processes closed successfully.
========================= Folder: C:\Users\Blaze\AppData\Local\CrashDumps ========================
2016-03-31 03:01 - 2016-03-31 03:01 - 3635691 _____ () C:\Users\Blaze\AppData\Local\CrashDumps\explorer.exe.4124.dmp
2016-02-18 22:17 - 2016-02-18 22:17 - 9975950 _____ () C:\Users\Blaze\AppData\Local\CrashDumps\Steam.exe.8084.dmp
2016-01-29 20:58 - 2016-01-29 20:58 - 22711169 _____ () C:\Users\Blaze\AppData\Local\CrashDumps\TheDivision.exe.5052.dmp
2016-01-30 18:59 - 2016-01-30 18:59 - 22497131 _____ () C:\Users\Blaze\AppData\Local\CrashDumps\TheDivision.exe.7720.dmp
2015-12-28 22:28 - 2015-12-28 22:28 - 0569266 _____ () C:\Users\Blaze\AppData\Local\CrashDumps\WWAHost.exe.14512.dmp
2016-02-02 00:07 - 2016-02-02 00:07 - 0566546 _____ () C:\Users\Blaze\AppData\Local\CrashDumps\WWAHost.exe.21352.dmp
2016-01-21 01:08 - 2016-01-21 01:08 - 0537426 _____ () C:\Users\Blaze\AppData\Local\CrashDumps\WWAHost.exe.50052.dmp
====== End of Folder: ======
========================= File: C:\Program Files (x86)\Common Files\BattlEye\BEService.exe ========================
File is digitally signed
MD5: 8C3E38D724D5AEF4D979C321B7054BF8
Creation and modification date: 2015-04-09 12:13 - 2016-02-11 17:48
Size: 1345056
Attributes: ----A
Company Name:
Internal Name:
Original Name:
Product:
Description:
File Version:
Product Version:
Copyright:
====== End of File: ======
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\NvBackend => value removed successfully
HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\ => value removed successfully
"C:\PROGRA~2\NVIDIA~1\3DVISI~1\NVSTIN~1.DLL" => Value data removed successfully.
HKU\.DEFAULT\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => value removed successfully
HKU\S-1-5-19\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => value removed successfully
HKU\S-1-5-20\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => value removed successfully
"HKU\S-1-5-21-2968257316-2402521077-608179223-1002\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{3676BAB6-88A8-4791-BB0D-29235C336008}" => key removed successfully
HKCR\CLSID\{3676BAB6-88A8-4791-BB0D-29235C336008} => key not found.
C:\ProgramData\Malwarebytes' Anti-Malware (portable) => moved successfully
C:\Users\Blaze\Desktop\mbar => moved successfully
C:\Users\Blaze\Desktop\mbar-1.09.3.1001.exe => moved successfully
C:\Users\Blaze\Downloads\adwcleaner_5.108.exe => moved successfully
C:\rsit => moved successfully
C:\AdwCleaner => moved successfully
C:\Program Files\trend micro => moved successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{6D3A0717-BB62-4C48-96E0-FB2F10DCF092}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{6D3A0717-BB62-4C48-96E0-FB2F10DCF092}" => key removed successfully
C:\WINDOWS\System32\Tasks\{C46BF320-C4B0-46EE-A6B9-83DCE8692288} => moved successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{C46BF320-C4B0-46EE-A6B9-83DCE8692288}" => key removed successfully
Fix result of Farbar Recovery Scan Tool (x64) Version:05-03-2016 01
Ran by Blaze (2016-04-01 00:59:14) Run:1
Running from C:\Users\Blaze\Desktop
Loaded Profiles: Blaze (Available Profiles: Blaze)
Boot Mode: Normal
==============================================
fixlist content:
*****************
Start
CreateRestorePoint:
CloseProcesses:
Folder: C:\Users\Blaze\AppData\Local\CrashDumps
File: C:\Program Files (x86)\Common Files\BattlEye\BEService.exe
HKLM\...\Run: [NvBackend] => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe [2396096 2016-03-30] (NVIDIA Corporation)
HKLM-x32\...\Run: [] => [X]
AppInit_DLLs: C:\PROGRA~2\NVIDIA~1\3DVISI~1\NVSTIN~1.DLL => No File
SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-21-2968257316-2402521077-608179223-1002 -> {3676BAB6-88A8-4791-BB0D-29235C336008} URL =
2016-03-31 01:35 - 2016-03-31 02:32 - 00000000 ____D C:\ProgramData\Malwarebytes' Anti-Malware (portable)
2016-03-31 01:33 - 2016-03-31 02:32 - 00000000 ____D C:\Users\Blaze\Desktop\mbar
2016-03-31 01:32 - 2016-03-31 01:32 - 16563352 _____ (Malwarebytes Corp.) C:\Users\Blaze\Desktop\mbar-1.09.3.1001.exe
2016-03-31 01:03 - 2016-03-31 01:03 - 03102720 _____ C:\Users\Blaze\Downloads\adwcleaner_5.108.exe
2016-03-30 22:29 - 2016-03-30 22:29 - 00000000 ____D C:\rsit
2016-03-31 01:06 - 2015-06-06 20:07 - 00000000 ____D C:\AdwCleaner
2016-03-30 22:29 - 2015-04-10 11:00 - 00000000 ____D C:\Program Files\trend micro
Task: {6D3A0717-BB62-4C48-96E0-FB2F10DCF092} - System32\Tasks\{C46BF320-C4B0-46EE-A6B9-83DCE8692288} => pcalua.exe -a C:\Users\Blaze\AppData\Roaming\ICQM\icqsetup.exe -c -uninstallcu
EmptyTemp:
End
*****************
Restore point was successfully created.
Processes closed successfully.
========================= Folder: C:\Users\Blaze\AppData\Local\CrashDumps ========================
2016-03-31 03:01 - 2016-03-31 03:01 - 3635691 _____ () C:\Users\Blaze\AppData\Local\CrashDumps\explorer.exe.4124.dmp
2016-02-18 22:17 - 2016-02-18 22:17 - 9975950 _____ () C:\Users\Blaze\AppData\Local\CrashDumps\Steam.exe.8084.dmp
2016-01-29 20:58 - 2016-01-29 20:58 - 22711169 _____ () C:\Users\Blaze\AppData\Local\CrashDumps\TheDivision.exe.5052.dmp
2016-01-30 18:59 - 2016-01-30 18:59 - 22497131 _____ () C:\Users\Blaze\AppData\Local\CrashDumps\TheDivision.exe.7720.dmp
2015-12-28 22:28 - 2015-12-28 22:28 - 0569266 _____ () C:\Users\Blaze\AppData\Local\CrashDumps\WWAHost.exe.14512.dmp
2016-02-02 00:07 - 2016-02-02 00:07 - 0566546 _____ () C:\Users\Blaze\AppData\Local\CrashDumps\WWAHost.exe.21352.dmp
2016-01-21 01:08 - 2016-01-21 01:08 - 0537426 _____ () C:\Users\Blaze\AppData\Local\CrashDumps\WWAHost.exe.50052.dmp
====== End of Folder: ======
========================= File: C:\Program Files (x86)\Common Files\BattlEye\BEService.exe ========================
File is digitally signed
MD5: 8C3E38D724D5AEF4D979C321B7054BF8
Creation and modification date: 2015-04-09 12:13 - 2016-02-11 17:48
Size: 1345056
Attributes: ----A
Company Name:
Internal Name:
Original Name:
Product:
Description:
File Version:
Product Version:
Copyright:
====== End of File: ======
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\NvBackend => value removed successfully
HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\ => value removed successfully
"C:\PROGRA~2\NVIDIA~1\3DVISI~1\NVSTIN~1.DLL" => Value data removed successfully.
HKU\.DEFAULT\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => value removed successfully
HKU\S-1-5-19\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => value removed successfully
HKU\S-1-5-20\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => value removed successfully
"HKU\S-1-5-21-2968257316-2402521077-608179223-1002\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{3676BAB6-88A8-4791-BB0D-29235C336008}" => key removed successfully
HKCR\CLSID\{3676BAB6-88A8-4791-BB0D-29235C336008} => key not found.
C:\ProgramData\Malwarebytes' Anti-Malware (portable) => moved successfully
C:\Users\Blaze\Desktop\mbar => moved successfully
C:\Users\Blaze\Desktop\mbar-1.09.3.1001.exe => moved successfully
C:\Users\Blaze\Downloads\adwcleaner_5.108.exe => moved successfully
C:\rsit => moved successfully
C:\AdwCleaner => moved successfully
C:\Program Files\trend micro => moved successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{6D3A0717-BB62-4C48-96E0-FB2F10DCF092}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{6D3A0717-BB62-4C48-96E0-FB2F10DCF092}" => key removed successfully
C:\WINDOWS\System32\Tasks\{C46BF320-C4B0-46EE-A6B9-83DCE8692288} => moved successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{C46BF320-C4B0-46EE-A6B9-83DCE8692288}" => key removed successfully
Re: Zasekany notebook
Je-li tohle opravdu kompletni obsah fixlogu, vytvorte novy fixlist a do nej vlozte
postup je naprosto stejny jako v predchazejicim kroku.
Kód: Vybrat vše
Start
EmptyTemp:
EndPokud je cokoliv nejasného, ihned se ptej.
V případě spokojenosti prosím podpořte forum.
Pro dotazy, které se nehodí na forum, je možné využít altrokzavináčforum.viry.cz
Máš-li chuť pomáhat návštěvníkům tohoto fora, přihlas se do naší školičky.
V případě spokojenosti prosím podpořte forum.
Pro dotazy, které se nehodí na forum, je možné využít altrokzavináčforum.viry.cz
Máš-li chuť pomáhat návštěvníkům tohoto fora, přihlas se do naší školičky.
Re: Zasekany notebook
Dobrý den. No ono se to prohledávání tak v půlce zaseklo, já čekal přes hodinu jestli se to pohne, ale nepohnulo. Tak jsem restartoval celý PC a tohle mi to hodilo. Jestli myslíte že se to špatně zkontrolovalo, co mám teda udělat?
Re: Zasekany notebook
Pokud takova nestandardni situace nastane, je lepsi o tom dat vedet 
Udelejte prosim krok, ktery jsem napsal v mem predchozim prispevku (3 řádky ve fixlistu).
Udelejte prosim krok, ktery jsem napsal v mem predchozim prispevku (3 řádky ve fixlistu).
Pokud je cokoliv nejasného, ihned se ptej.
V případě spokojenosti prosím podpořte forum.
Pro dotazy, které se nehodí na forum, je možné využít altrokzavináčforum.viry.cz
Máš-li chuť pomáhat návštěvníkům tohoto fora, přihlas se do naší školičky.
V případě spokojenosti prosím podpořte forum.
Pro dotazy, které se nehodí na forum, je možné využít altrokzavináčforum.viry.cz
Máš-li chuť pomáhat návštěvníkům tohoto fora, přihlas se do naší školičky.
Re: Zasekany notebook
Dobry vecer. Posilam ten fixlog.
Fix result of Farbar Recovery Scan Tool (x64) Version:05-03-2016 01
Ran by Blaze (2016-04-01 22:00:18) Run:2
Running from C:\Users\Blaze\Desktop
Loaded Profiles: Blaze (Available Profiles: Blaze)
Boot Mode: Normal
==============================================
fixlist content:
*****************
Start
EmptyTemp:
End
*****************
EmptyTemp: => 605 MB temporary data Removed.
The system needed a reboot.
==== End of Fixlog 22:00:57 ====
Fix result of Farbar Recovery Scan Tool (x64) Version:05-03-2016 01
Ran by Blaze (2016-04-01 22:00:18) Run:2
Running from C:\Users\Blaze\Desktop
Loaded Profiles: Blaze (Available Profiles: Blaze)
Boot Mode: Normal
==============================================
fixlist content:
*****************
Start
EmptyTemp:
End
*****************
EmptyTemp: => 605 MB temporary data Removed.
The system needed a reboot.
==== End of Fixlog 22:00:57 ====
Re: Zasekany notebook
Ve FRST logu jiz zadnou skodnou nevidim, takze pozorujte, jak se chova PC. Pripadne uz jen uklidime pouzite nastroje.
Pokud je cokoliv nejasného, ihned se ptej.
V případě spokojenosti prosím podpořte forum.
Pro dotazy, které se nehodí na forum, je možné využít altrokzavináčforum.viry.cz
Máš-li chuť pomáhat návštěvníkům tohoto fora, přihlas se do naší školičky.
V případě spokojenosti prosím podpořte forum.
Pro dotazy, které se nehodí na forum, je možné využít altrokzavináčforum.viry.cz
Máš-li chuť pomáhat návštěvníkům tohoto fora, přihlas se do naší školičky.
Re: Zasekany notebook
Dobře. Díky za pomoc.


Přispějete na provoz fóra?