Dobrý den,,,
tak jednou denně určitě,, vypnul sem automatický restart, tak až to přijde tak vyfotím mobilem,,,
tady jsou logy ---
a v příloze
Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version:05-03-2016 01
Ran by ROCOR (administrator) on ROCOR-PC (10-04-2016 09:56:19)
Running from C:\Users\ROCOR\Desktop
Loaded Profiles: ROCOR (Available Profiles: ROCOR)
Platform: Windows 7 Home Premium Service Pack 1 (X64) Language: Čeština (Česká republika)
Internet Explorer Version 11 (Default browser not detected!)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool:
http://www.geekstogo.com/forum/topic/33 ... scan-tool/
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
() C:\Windows\runservice.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
() C:\Windows\SysWOW64\HsMgr.exe
() C:\Windows\system\HsMgr64.exe
(CMedia) C:\Program Files\ASUS Xonar Essence ST Audio\Customapp\AsusAudioCenter.exe
() C:\Program Files (x86)\Fujitsu\LASER MOUSE\1.0\GTGMouse.exe
(Almico Software (
http://www.almico.com)) C:\Program Files (x86)\SpeedFan\speedfan.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe
(Learsy) C:\Program Files (x86)\MuralPix\MpAgent.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamService.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamNetworkService.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamUserAgent.exe
(BitTorrent, Inc.) C:\Program Files (x86)\uTorrent\uTorrent.exe
(forum.viry.cz) C:\Users\ROCOR\Desktop\FRSTLauncher.exe
==================== Registry (Whitelisted) ===========================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [Cmaudio8788] => C:\Windows\syswow64\RunDll32.exe C:\Windows\Syswow64\cmicnfgp.dll,CMICtrlWnd
HKLM\...\Run: [Cmaudio8788GX] => C:\Windows\syswow64\HsMgr.exe [200704 2008-07-11] ()
HKLM\...\Run: [Cmaudio8788GX64] => C:\Windows\system\HsMgr64.exe [282112 2008-07-11] ()
HKLM\...\Run: [NvBackend] => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe [2396096 2016-03-30] (NVIDIA Corporation)
HKLM\...\Run: [ShadowPlay] => "C:\Windows\system32\rundll32.exe" C:\Windows\system32\nvspcap64.dll,ShadowPlayOnSystemStart
HKLM-x32\...\Run: [USB3MON] => C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe [291608 2012-02-27] (Intel Corporation)
HKLM-x32\...\Run: [MuralPixAgent] => C:\Program Files (x86)\MuralPix\MpAgent.exe [102400 2006-12-30] (Learsy)
HKLM-x32\...\Run: [mnciureSrv] => C:\Windows\inf\mnciure.vbe
HKLM-x32\...\Run: [WindowsDriverScan86] => C:\Program Files (x86)\Adobe Arkalis\Arkalis86.lnk [1501 2014-08-10] ()
HKLM-x32\...\Run: [WindowsDriverScan64] => C:\Program Files (x86)\Adobe Arkalis\Arkalis.lnk [1419 2014-08-10] ()
Winlogon\Notify\igfxcui: igfxdev.dll [X]
HKU\S-1-5-21-866583909-2925738967-381583198-1000\...\Run: [DAEMON Tools Lite] => C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe [3696912 2014-03-04] (Disc Soft Ltd)
HKU\S-1-5-21-866583909-2925738967-381583198-1000\...\Run: [SpybotPostWindows10UpgradeReInstall] => C:\Program Files\Common Files\AV\Spybot - Search and Destroy\Test.exe [1011200 2015-07-28] (Safer-Networking Ltd.)
HKU\S-1-5-21-866583909-2925738967-381583198-1000\...\Policies\system: [DisableLockWorkstation] 0
HKU\S-1-5-21-866583909-2925738967-381583198-1000\Control Panel\Desktop\\SCRNSAVE.EXE -> C:\Windows\SysWOW64\MuralPix.scr [106496 2006-12-30] (Learsy)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\GTGMouse – zástupce.lnk [2014-05-24]
ShortcutTarget: GTGMouse – zástupce.lnk -> C:\Program Files (x86)\Fujitsu\LASER MOUSE\1.0\GTGMouse.exe ()
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\speedfan.lnk [2014-12-29]
ShortcutTarget: speedfan.lnk -> C:\Program Files (x86)\SpeedFan\speedfan.exe (Almico Software (
http://www.almico.com))
BootExecute: autocheck autochk * sdnclean64.exe
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
Hosts: There are more than one entry in Hosts. See Hosts section of Addition.txt
Tcpip\Parameters: [DhcpNameServer] 192.168.5.1 172.21.1.1 172.21.1.2
Tcpip\..\Interfaces\{5D68AF5B-E0C1-4DEB-9DFF-C6D54AEF83C0}: [DhcpNameServer] 192.168.5.1 172.21.1.1 172.21.1.2
Internet Explorer:
==================
HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page =
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL =
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL =
HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Local Page =
DPF: HKLM-x32 {D27CDB6E-AE6D-11CF-96B8-444553540000} hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
FireFox:
========
FF ProfilePath: C:\Users\ROCOR\AppData\Roaming\Mozilla\Firefox\Profiles\btckirlh.default
FF Homepage: hxxp://
www.vinaturae.com/eshop/authentication. ... istory.php
FF Session Restore: -> is enabled.
FF NetworkProxy: "type", 0
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_21_0_0_213.dll [2016-04-07] ()
FF Plugin: @esn/npbattlelog,version=2.6.2 -> C:\Program Files (x86)\Battlelog Web Plugins\2.6.2\npbattlelogx64.dll [No File]
FF Plugin: @esn/npbattlelog,version=2.7.1 -> C:\Program Files (x86)\Battlelog Web Plugins\2.7.1\npbattlelogx64.dll [2015-04-30] (EA Digital Illusions CE AB)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_21_0_0_213.dll [2016-04-07] ()
FF Plugin-x32: @adobe.com/ShockwavePlayer -> C:\Windows\SysWOW64\Adobe\Director\np32dsw_1213153.dll [2014-06-24] (Adobe Systems, Inc.)
FF Plugin-x32: @esn/npbattlelog,version=2.6.2 -> C:\Program Files (x86)\Battlelog Web Plugins\2.6.2\npbattlelog.dll [No File]
FF Plugin-x32: @esn/npbattlelog,version=2.7.1 -> C:\Program Files (x86)\Battlelog Web Plugins\2.7.1\npbattlelog.dll [2015-04-30] (EA Digital Illusions CE AB)
FF Plugin-x32: @Google.com/GoogleEarthPlugin -> C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll [2013-07-12] (Google)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll [2015-12-18] (Adobe Systems Inc.)
FF SearchPlugin: C:\Users\ROCOR\AppData\Roaming\Mozilla\Firefox\Profiles\btckirlh.default\searchplugins\alza.xml [2015-11-13]
FF SearchPlugin: C:\Users\ROCOR\AppData\Roaming\Mozilla\Firefox\Profiles\btckirlh.default\searchplugins\bratrstvnet.xml [2016-03-31]
FF SearchPlugin: C:\Users\ROCOR\AppData\Roaming\Mozilla\Firefox\Profiles\btckirlh.default\searchplugins\divinity-wiki-en.xml [2015-07-10]
FF SearchPlugin: C:\Users\ROCOR\AppData\Roaming\Mozilla\Firefox\Profiles\btckirlh.default\searchplugins\doplky-pro-firefox.xml [2014-05-02]
FF SearchPlugin: C:\Users\ROCOR\AppData\Roaming\Mozilla\Firefox\Profiles\btckirlh.default\searchplugins\fallout-wiki-en.xml [2016-01-02]
FF SearchPlugin: C:\Users\ROCOR\AppData\Roaming\Mozilla\Firefox\Profiles\btckirlh.default\searchplugins\fextralife-wikis-bloodborne.xml [2015-03-29]
FF SearchPlugin: C:\Users\ROCOR\AppData\Roaming\Mozilla\Firefox\Profiles\btckirlh.default\searchplugins\fextralife-wikis-darksouls2.xml [2014-04-02]
FF SearchPlugin: C:\Users\ROCOR\AppData\Roaming\Mozilla\Firefox\Profiles\btckirlh.default\searchplugins\fextralife-wikis-dragonage3.xml [2015-01-14]
FF SearchPlugin: C:\Users\ROCOR\AppData\Roaming\Mozilla\Firefox\Profiles\btckirlh.default\searchplugins\fextralife-wikis-lordsofthefallen.xml [2016-01-20]
FF SearchPlugin: C:\Users\ROCOR\AppData\Roaming\Mozilla\Firefox\Profiles\btckirlh.default\searchplugins\imdb.xml [2016-04-08]
FF SearchPlugin: C:\Users\ROCOR\AppData\Roaming\Mozilla\Firefox\Profiles\btckirlh.default\searchplugins\katcr.xml [2016-03-31]
FF SearchPlugin: C:\Users\ROCOR\AppData\Roaming\Mozilla\Firefox\Profiles\btckirlh.default\searchplugins\opensubtitles.xml [2015-10-06]
FF SearchPlugin: C:\Users\ROCOR\AppData\Roaming\Mozilla\Firefox\Profiles\btckirlh.default\searchplugins\secure-torrentz-search.xml [2016-03-31]
FF SearchPlugin: C:\Users\ROCOR\AppData\Roaming\Mozilla\Firefox\Profiles\btckirlh.default\searchplugins\sfd.xml [2016-04-10]
FF SearchPlugin: C:\Users\ROCOR\AppData\Roaming\Mozilla\Firefox\Profiles\btckirlh.default\searchplugins\torrent-metasearch.xml [2013-05-20]
FF SearchPlugin: C:\Users\ROCOR\AppData\Roaming\Mozilla\Firefox\Profiles\btckirlh.default\searchplugins\uloto.xml [2015-10-22]
FF SearchPlugin: C:\Users\ROCOR\AppData\Roaming\Mozilla\Firefox\Profiles\btckirlh.default\searchplugins\vyhledvn-vide-ve-slub-youtube.xml [2015-08-20]
FF SearchPlugin: C:\Users\ROCOR\AppData\Roaming\Mozilla\Firefox\Profiles\btckirlh.default\searchplugins\wordpresscom.xml [2016-03-31]
FF Extension: Flash Game Maximizer - C:\Users\ROCOR\AppData\Roaming\Mozilla\Firefox\Profiles\btckirlh.default\extensions\{258735dc-6743-4805-95fc-f95941fffdad}.xpi [2015-05-30]
FF Extension: Tab Mix Plus - C:\Users\ROCOR\AppData\Roaming\Mozilla\Firefox\Profiles\btckirlh.default\extensions\{dc572301-7619-498c-a57d-39143191b318}.xpi [2015-06-18]
FF Extension: Adblock Plus Pop-up Addon - C:\Users\ROCOR\AppData\Roaming\Mozilla\Firefox\Profiles\btckirlh.default\extensions\
adblockpopups@jessehakanen.net.xpi [2015-08-19]
FF Extension: ImageBlock - C:\Users\ROCOR\AppData\Roaming\Mozilla\Firefox\Profiles\btckirlh.default\extensions\
imageblock@hemantvats.com.xpi [2016-04-04]
FF Extension: Český slovník pro kontrolu pravopisu (bez diakritiky) - C:\Users\ROCOR\AppData\Roaming\Mozilla\Firefox\Profiles\btckirlh.default\Extensions\
cs2@dictionaries.addons.mozilla.org [2016-01-22]
FF Extension: Český slovník pro kontrolu pravopisu - C:\Users\ROCOR\AppData\Roaming\Mozilla\Firefox\Profiles\btckirlh.default\Extensions\
cs@dictionaries.addons.mozilla.org [2016-01-10]
FF Extension: Element Hiding Helper for Adblock Plus - C:\Users\ROCOR\AppData\Roaming\Mozilla\Firefox\Profiles\btckirlh.default\Extensions\
elemhidehelper@adblockplus.org.xpi [2015-08-19]
FF Extension: NASA Night Launch - C:\Users\ROCOR\AppData\Roaming\Mozilla\Firefox\Profiles\btckirlh.default\Extensions\
nasanightlaunch@example.com.xpi [2014-12-21] [not signed]
FF Extension: Flagfox - C:\Users\ROCOR\AppData\Roaming\Mozilla\Firefox\Profiles\btckirlh.default\Extensions\{1018e4d6-728f-4b20-ad56-37578a4de76b}(2) [2014-12-20] [not signed]
FF Extension: Flagfox - C:\Users\ROCOR\AppData\Roaming\Mozilla\Firefox\Profiles\btckirlh.default\Extensions\{1018e4d6-728f-4b20-ad56-37578a4de76b}(3) [2014-12-20] [not signed]
FF Extension: Flagfox - C:\Users\ROCOR\AppData\Roaming\Mozilla\Firefox\Profiles\btckirlh.default\Extensions\{1018e4d6-728f-4b20-ad56-37578a4de76b}.xpi [2016-03-18]
FF Extension: Session Manager - C:\Users\ROCOR\AppData\Roaming\Mozilla\Firefox\Profiles\btckirlh.default\Extensions\{1280606b-2510-4fe0-97ef-9b5a22eafe30}.xpi [2015-07-08]
FF Extension: BitComet Video Downloader - C:\Users\ROCOR\AppData\Roaming\Mozilla\Firefox\Profiles\btckirlh.default\Extensions\{B042753D-F57E-4e8e-A01B-7379A6D4CEFB}(2) [2014-12-20] [not signed]
FF Extension: BitComet Video Downloader - C:\Users\ROCOR\AppData\Roaming\Mozilla\Firefox\Profiles\btckirlh.default\Extensions\{B042753D-F57E-4e8e-A01B-7379A6D4CEFB}(3) [2014-12-20] [not signed]
FF Extension: No Name - C:\Users\ROCOR\AppData\Roaming\Mozilla\Firefox\Profiles\btckirlh.default\Extensions\{B042753D-F57E-4e8e-A01B-7379A6D4CEFB}-trash [2014-12-20] [not signed]
FF Extension: Adblock Plus - C:\Users\ROCOR\AppData\Roaming\Mozilla\Firefox\Profiles\btckirlh.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}(2) [2014-12-20] [not signed]
FF Extension: Adblock Plus - C:\Users\ROCOR\AppData\Roaming\Mozilla\Firefox\Profiles\btckirlh.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}(3) [2014-12-20] [not signed]
FF Extension: Adblock Plus - C:\Users\ROCOR\AppData\Roaming\Mozilla\Firefox\Profiles\btckirlh.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2015-08-19]
FF Extension: Adblock Edge - C:\Users\ROCOR\AppData\Roaming\Mozilla\Firefox\Profiles\btckirlh.default\Extensions\{fe272bd1-5f76-4ea4-8501-a05d35d823fc}.xpi [2015-12-04]
==================== Services (Whitelisted) ========================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R2 GfExperienceService; C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe [1163200 2016-03-30] (NVIDIA Corporation)
S3 igfxCUIService1.0.0.0; C:\Windows\system32\igfxCUIService.exe [330136 2015-08-27] (Intel Corporation)
R2 LicCtrlService; C:\Windows\runservice.exe [16384 2014-10-08] () [File not signed]
S4 MBAMScheduler; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe [1513784 2015-10-05] (Malwarebytes)
S2 MBAMService; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe [1135416 2015-10-05] (Malwarebytes)
R2 NvNetworkService; C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe [1879488 2016-03-30] (NVIDIA Corporation)
R3 NvStreamNetworkSvc; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamNetworkService.exe [3632576 2016-03-30] (NVIDIA Corporation)
R2 NvStreamSvc; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamService.exe [2521024 2016-03-30] (NVIDIA Corporation)
S3 Origin Client Service; C:\Program Files (x86)\Origin\OriginClientService.exe [2007048 2015-08-01] (Electronic Arts)
S3 PinnacleUpdateSvc; C:\Program Files (x86)\PowerUp Software\Pinnacle Game Profiler\pinnacle_updater.exe [438272 2014-01-12] (PowerUp Software, LLC) [File not signed]
S4 PnkBstrA; C:\Windows\SysWOW64\PnkBstrA.exe [76152 2015-03-21] ()
S4 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2013-05-27] (Microsoft Corporation)
===================== Drivers (Whitelisted) ==========================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R0 asahci64; C:\Windows\System32\DRIVERS\asahci64.sys [49760 2011-09-21] (Asmedia Technology)
R0 AsrRamDisk; C:\Windows\System32\DRIVERS\AsrRamDisk.sys [31016 2012-01-13] (ASRock Inc.)
R3 cmudaxp; C:\Windows\System32\drivers\cmudaxp.sys [2725376 2011-03-10] (C-Media Inc)
R1 dtsoftbus01; C:\Windows\System32\DRIVERS\dtsoftbus01.sys [283064 2015-02-13] (Disc Soft Ltd)
S3 ebdrv; C:\Windows\system32\drivers\evbda.sys [3286016 2009-06-10] (Broadcom Corporation)
R3 FNETTBOH_305; C:\Windows\System32\drivers\FNETTBOH_305.SYS [32320 2014-12-19] (FNet Co., Ltd.)
R1 FNETURPX; C:\Windows\System32\drivers\FNETURPX.SYS [16648 2014-12-19] (FNet Co., Ltd.)
R0 iaStorF; C:\Windows\System32\DRIVERS\iaStorF.sys [28216 2012-09-01] (Intel Corporation)
R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25816 2015-10-05] (Malwarebytes)
S3 MBAMWebAccessControl; C:\Windows\system32\drivers\mwac.sys [63704 2015-10-05] (Malwarebytes Corporation)
S3 MZ_USBAUDIO; C:\Windows\System32\drivers\mz_usbaudio.sys [146944 2012-12-13] (D&M Holdings Inc.) [File not signed]
R3 NvStreamKms; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys [26560 2016-03-30] (NVIDIA Corporation)
R3 nvvad_WaveExtensible; C:\Windows\System32\drivers\nvvad64v.sys [56384 2016-03-21] (NVIDIA Corporation)
==================== NetSvcs (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
==================== One Month Created files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2016-04-10 09:56 - 2016-04-10 09:56 - 00016715 _____ C:\Users\ROCOR\Desktop\FRST.txt
2016-04-10 09:55 - 2016-04-10 09:56 - 00000000 ____D C:\FRST
2016-04-10 09:55 - 2016-04-10 09:55 - 00112640 _____ (forum.viry.cz) C:\Users\ROCOR\Desktop\FRSTLauncher.exe
2016-04-10 09:54 - 2016-04-10 09:54 - 02374144 _____ (Farbar) C:\Users\ROCOR\Desktop\FRST64.exe
2016-04-10 03:14 - 2016-04-10 03:14 - 00000000 ____D C:\Windows\LastGood
2016-04-10 03:14 - 2016-03-21 22:01 - 00109632 _____ (NVIDIA Corporation) C:\Windows\system32\nvaudcap64v.dll
2016-04-10 03:14 - 2016-03-21 22:01 - 00100416 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvaudcap32v.dll
2016-04-10 03:14 - 2016-03-21 22:01 - 00056384 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvvad64v.sys
2016-04-09 07:50 - 2016-04-09 07:50 - 00000085 _____ C:\Windows\wininit.ini
2016-04-09 07:44 - 2016-04-09 07:44 - 00000000 ____D C:\Program Files\Common Files\AV
2016-04-09 07:40 - 2016-04-09 07:40 - 00000000 ____D C:\Windows\System32\Tasks\Safer-Networking
2016-04-07 19:46 - 2016-04-07 20:46 - 05934784 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerInstaller.exe
2016-03-17 10:02 - 2016-03-17 10:02 - 00000000 ____D C:\Users\ROCOR\AppData\Roaming\Ashampoo
2016-03-17 10:02 - 2016-03-17 10:02 - 00000000 ____D C:\Users\ROCOR\AppData\Local\ashampoo
2016-03-17 10:02 - 2016-03-17 10:02 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Ashampoo
2016-03-17 10:01 - 2016-03-17 10:02 - 00000000 ____D C:\ProgramData\Ashampoo
2016-03-17 10:01 - 2016-03-17 10:01 - 00000000 ____D C:\Program Files (x86)\Ashampoo
2016-03-12 18:34 - 2016-03-12 18:34 - 00000000 ____D C:\Users\ROCOR\AppData\Roaming\NVIDIA
==================== One Month Modified files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2016-04-10 09:56 - 2014-05-22 16:21 - 00000000 ____D C:\Users\ROCOR\AppData\Roaming\uTorrent
2016-04-10 09:52 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\inf
2016-04-10 09:46 - 2014-05-22 06:59 - 00000914 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job
2016-04-10 03:31 - 2014-05-23 07:01 - 00000000 ____D C:\ProgramData\boost_interprocess
2016-04-10 03:26 - 2014-05-22 07:19 - 00000000 ___RD C:\Users\ROCOR\Desktop\ROCOR
2016-04-10 03:19 - 2011-04-12 10:34 - 00648690 _____ C:\Windows\system32\perfh005.dat
2016-04-10 03:19 - 2011-04-12 10:34 - 00133548 _____ C:\Windows\system32\perfc005.dat
2016-04-10 03:19 - 2009-07-14 07:13 - 01527778 _____ C:\Windows\system32\PerfStringBackup.INI
2016-04-10 03:18 - 2009-07-14 06:45 - 00021616 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2016-04-10 03:18 - 2009-07-14 06:45 - 00021616 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2016-04-10 03:13 - 2014-12-29 19:22 - 00000000 ____D C:\Program Files (x86)\SpeedFan
2016-04-10 03:13 - 2014-10-08 13:37 - 00001369 ___SH C:\Windows\SysWOW64\mmf.sys
2016-04-10 03:13 - 2009-07-14 07:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2016-04-09 22:56 - 2014-12-29 17:06 - 00000000 ____D C:\Windows\Minidump
2016-04-09 19:59 - 2014-08-09 07:35 - 00003970 _____ C:\Windows\System32\Tasks\User_Feed_Synchronization-{DFE319C7-2C57-4D09-B67B-1589BD45581B}
2016-04-09 15:32 - 2014-05-22 07:13 - 00000000 ____D C:\Users\ROCOR\AppData\Roaming\foobar2000
2016-04-09 09:25 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\system32\NDF
2016-04-09 07:54 - 2014-05-22 14:03 - 00192216 _____ (Malwarebytes) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2016-04-07 20:46 - 2014-05-22 06:59 - 00797376 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2016-04-07 20:46 - 2014-05-22 06:59 - 00142528 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2016-04-07 20:46 - 2014-05-22 06:59 - 00003852 _____ C:\Windows\System32\Tasks\Adobe Flash Player Updater
2016-04-05 17:10 - 2016-01-20 06:32 - 00000000 ____D C:\Users\ROCOR\AppData\Local\CrashDumps
2016-03-30 03:06 - 2015-03-21 15:54 - 01373680 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvspcap.dll
2016-03-30 03:06 - 2015-03-21 15:54 - 01316000 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvspbridge.dll
2016-03-30 03:05 - 2016-01-12 09:49 - 00112216 _____ C:\Windows\system32\NvRtmpStreamer64.dll
2016-03-30 03:05 - 2015-03-21 15:54 - 01767248 _____ (NVIDIA Corporation) C:\Windows\system32\nvspcap64.dll
2016-03-30 03:05 - 2015-03-21 15:54 - 01756424 _____ (NVIDIA Corporation) C:\Windows\system32\nvspbridge64.dll
2016-03-28 21:07 - 2014-06-18 13:17 - 00001209 _____ C:\Users\ROCOR\AppData\Roaming\Microsoft\Windows\Start Menu\GOM Player.lnk
2016-03-16 17:06 - 2014-07-09 17:43 - 00000000 ____D C:\Users\ROCOR\Documents\EQ_Foobar2000
2016-03-12 18:34 - 2014-05-23 06:59 - 00000000 ____D C:\Users\ROCOR\AppData\Roaming\tigerplayer
2016-03-12 09:13 - 2014-05-23 21:30 - 00007632 _____ C:\Users\ROCOR\AppData\Local\Resmon.ResmonCfg
==================== Files in the root of some directories =======
2014-05-22 07:02 - 2014-05-22 07:02 - 0000600 _____ () C:\Users\ROCOR\AppData\Roaming\winscp.rnd
2014-08-10 11:22 - 2014-08-10 11:22 - 0000058 _____ () C:\Users\ROCOR\AppData\Local\DonationCoder_ScreenshotCaptor_InstallInfo.dat
2014-05-23 21:30 - 2016-03-12 09:13 - 0007632 _____ () C:\Users\ROCOR\AppData\Local\Resmon.ResmonCfg
2014-05-24 18:48 - 2014-05-24 18:48 - 0000003 _____ () C:\Users\ROCOR\AppData\Local\user_data.ini
Some files in TEMP:
====================
C:\Users\ROCOR\AppData\Local\Temp\sfamcc00001.dll
C:\Users\ROCOR\AppData\Local\Temp\sfareca00001.dll
==================== Bamital & volsnap =================
(There is no automatic fix for files that do not pass verification.)
C:\Windows\system32\winlogon.exe => File is digitally signed
C:\Windows\system32\wininit.exe => File is digitally signed
C:\Windows\SysWOW64\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\system32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\system32\services.exe => File is digitally signed
C:\Windows\system32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\system32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\system32\rpcss.dll => File is digitally signed
C:\Windows\system32\dnsapi.dll => File is digitally signed
C:\Windows\SysWOW64\dnsapi.dll => File is digitally signed
C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed
LastRegBack: 2016-04-08 01:51
==================== End of FRST.txt ============================
===***===***===***=== Extract of Additional scan result of Farbar Recovery Scan Tool ===***===***===***===
==================== Drive and Memory info ===================
Drive c: () (Fixed) (Total:232.79 GB) (Free:92.34 GB) NTFS
Drive d: () (Fixed) (Total:931.51 GB) (Free:148.99 GB) NTFS
Drive f: (Rezervováno systémem) (Fixed) (Total:0.1 GB) (Free:0.06 GB) NTFS ==>[system with boot components (obtained from drive)]
Drive g: (VERBATIM HD) (Fixed) (Total:465.64 GB) (Free:11.16 GB) FAT32
Available physical RAM: 6510.53 MB
Total physical RAM: 8076.4 MB
Percentage of memory in use: 19%
==================== MBR and Partition Table ==================
Disk: 0 (MBR Code: Windows 7 or 8) (Size: 232.9 GB) (Disk ID: 0BA592B7)
Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=232.8 GB) - (Type=07 NTFS)
Disk: 1 (MBR Code: Windows 7 or 8) (Size: 931.5 GB) (Disk ID: 5814E5E1)
Partition 1: (Not Active) - (Size=931.5 GB) - (Type=07 NTFS)
Disk: 2 (Size: 465.8 GB) (Disk ID: A345F4C7)
Partition 1: (Not Active) - (Size=465.8 GB) - (Type=0C)
==================== Scheduled Tasks (whitelisted) ==================
(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)
Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
==================== Alternate Data Streams (whitelisted) ==================
AlternateDataStreams: C:\Windows\SysWOW64\zlib.dll:DocumentSummaryInformation [43]
AlternateDataStreams: C:\Windows\SysWOW64\zlib.dll:SummaryInformation [43]
AlternateDataStreams: C:\Windows\SysWOW64\zlib.dll:{4c8cc155-6c1e-11d1-8e41-00c04fb9386d} [0]
==================== Security Center ==================
AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
===***===***===***=== Supplementary Scan createdy by FRSTLauncher ===***===***===***===
Posledni aktualizace FRSTLauncheru: 25_11_2013 (01)
Posledni aktualizace Modifikacniho skriptu: 30_09_2013 (01)
***** Velikost "Plochy" *****
Velikost slozky "C:\Users\ROCOR\Desktop" je 8122 MB.
***** Startup Programs *****
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Users^ROCOR^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^MpManag.lnk
C:\PROGRA~2\MuralPix\MpManag.exe
***** Firewall rules *****
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
EnableFirewall REG_DWORD 0x1
DisableNotifications REG_DWORD 0x0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
EnableFirewall REG_DWORD 0x1
DisableNotifications REG_DWORD 0x0
DoNotAllowExceptions REG_DWORD 0x0
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
***** System Restore *****
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"Generalize_DisableSR"=dword:00000000
==================== End Of Log ==============================