Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 20-06-2016 01
Ran by Damian (administrator) on DAMIAN-PC (23-06-2016 20:22:26)
Running from C:\Users\Damian\Desktop
Loaded Profiles: Damian (Available Profiles: Damian)
Platform: Windows 7 Ultimate Service Pack 1 (X64) Language: Angličtina (Spojené státy)
Internet Explorer Version 8 (Default browser: Chrome)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool:
http://www.geekstogo.com/forum/topic/33 ... scan-tool/
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(IObit) C:\Program Files (x86)\IObit\Advanced SystemCare\ASCService.exe
(AMD) C:\Windows\System32\atiesrxx.exe
(AMD) C:\Windows\System32\atieclxx.exe
(Apple Inc.) C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(Microsoft Corporation) C:\Program Files (x86)\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe
(Microsoft Corporation) C:\Program Files (x86)\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe
(IObit) C:\Program Files (x86)\IObit\Advanced SystemCare\Monitor.exe
(ESET) C:\Program Files\ESET\ESET Smart Security\x86\ekrn.exe
() C:\Program Files (x86)\freeSSHd\FreeSSHDService.exe
(Microsoft Corporation) C:\Program Files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Binn\sqlservr.exe
(Gigabyte Technology CO., LTD.) C:\Program Files (x86)\GIGABYTE\smart6\timelock\TimeMgmtDaemon.exe
(Microsoft Corporation) C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
(Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
(Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE
(Microsoft Corporation) C:\Windows\System32\rundll32.exe
(Gigabyte Technology CO.) C:\Program Files\GIGABYTE\SMART6\Recovery\RPMDaemon.exe
(Samsung Electronics.) C:\Program Files (x86)\Samsung Magician\Samsung Magician.exe
(Alienware Corporation) C:\Program Files\Alienware\Command Center\AlienwareAlienFXController.exe
(Alienware) C:\Program Files\Alienware\Alienware TactX Keyboard CI\txkbci.exe
(ESET) C:\Program Files\ESET\ESET Smart Security\egui.exe
(Mad Catz Inc) C:\Program Files\Mad Catz\M.O.U.S.9\MOUS9_Profiler.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
(Apple Inc.) C:\Program Files\iTunes\iTunesHelper.exe
(Microsoft Corporation) C:\Program Files\Windows Sidebar\sidebar.exe
(IObit) C:\Program Files (x86)\IObit\Advanced SystemCare\ASCTray.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(Microsoft Corporation) C:\Windows\SysWOW64\dllhost.exe
(Advanced Micro Devices Inc.) C:\Program Files (x86)\AMD\ATI.ACE\Core-Static\MOM.exe
(Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe
(Raptr, Inc) C:\Program Files (x86)\Raptr Inc\Raptr\raptr.exe
(Advanced Micro Devices Inc.) C:\Program Files (x86)\AMD\ATI.ACE\Core-Static\CCC.exe
(Alienware) C:\Program Files\Alienware\Command Center\AlienFXHook32Mngr.exe
(Alienware) C:\Program Files\Alienware\Command Center\AlienFXHook64Mngr.exe
(Raptr, Inc) C:\Program Files (x86)\Raptr Inc\Raptr\raptr_im.exe
(Raptr Inc.) C:\Program Files (x86)\Raptr Inc\Raptr\raptr_ep64.exe
(Gigabyte Technology CO., LTD.) C:\Program Files (x86)\GIGABYTE\smart6\timelock\AlarmClock.exe
(IObit) C:\Program Files (x86)\IObit\IObit Uninstaller\UninstallMonitor.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
(ZeniMax Online Studios) C:\Program Files (x86)\Zenimax Online\Launcher\Bethesda.net_Launcher.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jucheck.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
() C:\Program Files (x86)\Zenimax Online\The Elder Scrolls Online EU\game\client\eso64.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Opera Software) C:\Program Files (x86)\Opera\38.0.2220.31\opera.exe
(Opera Software) C:\Program Files (x86)\Opera\38.0.2220.31\opera_crashreporter.exe
(Opera Software) C:\Program Files (x86)\Opera\38.0.2220.31\opera.exe
(Opera Software) C:\Program Files (x86)\Opera\38.0.2220.31\opera.exe
(Opera Software) C:\Program Files (x86)\Opera\38.0.2220.31\opera.exe
(Opera Software) C:\Program Files (x86)\Opera\38.0.2220.31\opera.exe
(Opera Software) C:\Program Files (x86)\Opera\38.0.2220.31\opera.exe
(forum.viry.cz) C:\Users\Damian\Desktop\FRSTLauncher.exe
(Microsoft Corporation) C:\Windows\SysWOW64\cmd.exe
(Microsoft Corporation) C:\Windows\SysWOW64\PING.EXE
==================== Registry (Whitelisted) ===========================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [AlienFX Controller] => C:\Program Files\Alienware\Command Center\AlienwareAlienFXController.exe [57672 2009-05-20] (Alienware Corporation)
HKLM\...\Run: [Launch Keyboard CI] => C:\Program Files\Alienware\Alienware TactX Keyboard CI\txkbci.exe [3438088 2009-05-28] (Alienware)
HKLM\...\Run: [egui] => C:\Program Files\ESET\ESET Smart Security\egui.exe [5617432 2013-08-19] (ESET)
HKLM\...\Run: [AutoKMS] => C:\Windows\AutoKMS.exe [615936 2013-11-23] ()
HKLM\...\Run: [M.O.U.S.9] => C:\Program Files\Mad Catz\M.O.U.S.9\MOUS9_Profiler.exe [55808 2015-03-17] (Mad Catz Inc)
HKLM\...\Run: [RtHDVCpl] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [16408320 2000-01-01] (Realtek Semiconductor)
HKLM\...\Run: [iTunesHelper] => C:\Program Files\iTunes\iTunesHelper.exe [176952 2016-03-19] (Apple Inc.)
HKLM\...\Run: [AdobeAAMUpdater-1.0] => C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [500936 2015-07-22] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [Raptr] => C:\Program Files (x86)\Raptr Inc\Raptr\raptrstub.exe [58640 2016-04-27] (Raptr, Inc)
HKLM-x32\...\Run: [StartCCC] => C:\Program Files (x86)\AMD\ATI.ACE\Core-Static\amd64\CLIStart.exe [767176 2015-08-04] (Advanced Micro Devices, Inc.)
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [597040 2015-12-22] (Oracle Corporation)
HKLM\...\RunOnce: [RPMKickstart] => C:\Program Files\GIGABYTE\SMART6\Recovery\RPMKickstart.exe [2552320 2011-03-30] (Gigabyte Technology CO., LTD.)
Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation)
HKU\S-1-5-21-3827235849-3457186460-974332170-1000\...\Run: [AdobeBridge] => [X]
HKU\S-1-5-21-3827235849-3457186460-974332170-1000\...\Run: [Advanced SystemCare 9] => C:\Program Files (x86)\IObit\Advanced SystemCare\ASCTray.exe [2010912 2015-11-06] (IObit)
HKU\S-1-5-21-3827235849-3457186460-974332170-1000\...\Run: [DAEMON Tools Lite] => C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe [3672640 2013-03-14] (Disc Soft Ltd)
HKU\S-1-5-21-3827235849-3457186460-974332170-1000\...\MountPoints2: {4f360db6-49ef-11e3-b619-50e5495778ae} - H:\setup.exe
HKU\S-1-5-18\...\Run: [Advanced SystemCare 9] => C:\Program Files (x86)\IObit\Advanced SystemCare\ASCTray.exe [2010912 2015-11-06] (IObit)
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
Hosts: There are more than one entry in Hosts. See Hosts section of Addition.txt
Tcpip\Parameters: [DhcpNameServer] 192.168.0.1
Tcpip\..\Interfaces\{6607A654-11D0-4991-8305-087C5B3AFBEB}: [DhcpNameServer] 192.168.42.129
Tcpip\..\Interfaces\{6C1BD4DE-A476-47BD-BD1E-7BC3E088B597}: [DhcpNameServer] 192.168.0.1
Tcpip\..\Interfaces\{8A1C7FA5-6E5D-4B03-9CD5-84E1ABFDF12F}: [DhcpNameServer] 172.20.10.1
Internet Explorer:
==================
SearchScopes: HKU\S-1-5-21-3827235849-3457186460-974332170-1000 -> DefaultScope {00A4DD73-CC7D-413c-8CCF-49FC4179109A} URL = hxxp://
www.google.com/cse?cx=partner-pub-37942 ... earchTerms}
SearchScopes: HKU\S-1-5-21-3827235849-3457186460-974332170-1000 -> {00A4DD73-CC7D-413c-8CCF-49FC4179109A} URL = hxxp://
www.google.com/cse?cx=partner-pub-37942 ... earchTerms}
SearchScopes: HKU\S-1-5-21-3827235849-3457186460-974332170-1000 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://
www.google.com/cse?cx=partner-pub-37942 ... earchTerms}
SearchScopes: HKU\S-1-5-21-3827235849-3457186460-974332170-1000 -> {906BA3FE-B9FD-4eea-B175-E45D01758A7B} URL = hxxp://
www.bing.com/search?q={searchTerms}&form=SPLBR1&pc=SPLH
SearchScopes: HKU\S-1-5-21-3827235849-3457186460-974332170-1000 -> {BE4654E6-7BD5-4f96-98B5-138F1B36B08B} URL = hxxp://uk.search.yahoo.com/search?p={searchTerms}&fr=chr-devicevm&type=IEBDSV
BHO: ExplorerWnd Helper -> {10921475-03CE-4E04-90CE-E2E7EF20C814} -> C:\Program Files (x86)\IObit\IObit Uninstaller\UninstallExplorer.dll [2015-11-12] (IObit)
BHO: GBHO.BHO -> {45d30484-7ded-43d9-957a-d2fd1f046511} -> C:\Windows\system32\mscoree.dll [2010-11-04] (Microsoft Corporation)
BHO: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL [2010-03-25] (Microsoft Corporation)
BHO: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2009-08-18] (Microsoft Corporation)
BHO: Skype Click to Call for Internet Explorer -> {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} -> C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll [2016-05-25] (Microsoft Corporation)
BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL [2010-02-28] (Microsoft Corporation)
BHO-x32: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files (x86)\Microsoft Office\Office14\GROOVEEX.DLL [2010-03-25] (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_72\bin\ssv.dll [2016-02-21] (Oracle Corporation)
BHO-x32: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2009-08-18] (Microsoft Corporation)
BHO-x32: Skype Click to Call for Internet Explorer -> {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} -> C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll [2016-05-25] (Microsoft Corporation)
BHO-x32: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL [2010-02-28] (Microsoft Corporation)
BHO-x32: Advanced SystemCare Surfing Protection -> {BA0C978D-D909-49B6-AFE2-8BDE245DC7E6} -> C:\Program Files (x86)\IObit\Surfing Protection\BrowerProtect\ASCPlugin_Protection.dll [2015-07-09] (IObit)
BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_72\bin\jp2ssv.dll [2016-02-21] (Oracle Corporation)
Toolbar: HKLM - Smart Recovery 2 - {1d09c093-f71e-43c3-b948-19316cbd695e} - C:\Windows\system32\mscoree.dll [2010-11-04] (Microsoft Corporation)
Toolbar: HKU\S-1-5-21-3827235849-3457186460-974332170-1000 -> No Name - {E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39} - No File
Toolbar: HKU\S-1-5-21-3827235849-3457186460-974332170-1000 -> No Name - {D4027C7F-154A-4066-A1AD-4243D8127440} - No File
Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll [2013-02-26] (Skype Technologies)
Handler: skypec2c - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll [2016-05-25] (Microsoft Corporation)
Handler-x32: skypec2c - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll [2016-05-25] (Microsoft Corporation)
Filter: deflate - {8f6b0360-b80d-11d0-a9b3-006097942311} - C:\Windows\system32\urlmon.dll [2015-12-10] (Microsoft Corporation)
Filter-x32: deflate - {8f6b0360-b80d-11d0-a9b3-006097942311} - C:\Windows\SysWOW64\urlmon.dll [2015-12-10] (Microsoft Corporation)
Filter: gzip - {8f6b0360-b80d-11d0-a9b3-006097942311} - C:\Windows\system32\urlmon.dll [2015-12-10] (Microsoft Corporation)
Filter-x32: gzip - {8f6b0360-b80d-11d0-a9b3-006097942311} - C:\Windows\SysWOW64\urlmon.dll [2015-12-10] (Microsoft Corporation)
FireFox:
========
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_22_0_0_192.dll [2016-06-17] ()
FF Plugin: @microsoft.com/GENUINE -> disabled [No File]
FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_22_0_0_192.dll [2016-06-17] ()
FF Plugin-x32: @Apple.com/iTunes,version=1.0 -> C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll [2016-03-08] ()
FF Plugin-x32: @foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/pdf -> C:\Program Files (x86)\Foxit Software\Foxit Reader\plugins\npFoxitReaderPlugin.dll [2011-07-19] (Foxit Corporation)
FF Plugin-x32: @IObit.com/np_Asc_Plugin -> C:\Program Files (x86)\IObit\Surfing Protection\BrowerProtect\np_Asc_plugin.dll [2013-07-17] (IObit)
FF Plugin-x32: @java.com/DTPlugin,version=11.72.2 -> C:\Program Files (x86)\Java\jre1.8.0_72\bin\dtplugin\npDeployJava1.dll [2016-02-21] (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=11.72.2 -> C:\Program Files (x86)\Java\jre1.8.0_72\bin\plugin2\npjp2.dll [2016-02-21] (Oracle Corporation)
FF Plugin-x32: @microsoft.com/GENUINE -> disabled [No File]
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files (x86)\Microsoft Silverlight\3.0.40818.0\npctrl.dll [2009-08-17] ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL [2010-03-24] (Microsoft Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.30.3\npGoogleUpdate3.dll [2016-05-11] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.30.3\npGoogleUpdate3.dll [2016-05-11] (Google Inc.)
FF Plugin-x32: @videolan.org/vlc,version=2.1.2 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2015-04-13] (VideoLAN)
FF Plugin-x32: @videolan.org/vlc,version=2.1.5 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2015-04-13] (VideoLAN)
FF Plugin-x32: @videolan.org/vlc,version=2.2.1 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2015-04-13] (VideoLAN)
FF Plugin HKU\S-1-5-21-3827235849-3457186460-974332170-1000: @unity3d.com/UnityPlayer,version=1.0 -> C:\Users\Damian\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll [2015-02-24] (Unity Technologies ApS)
FF HKLM-x32\...\Thunderbird\Extensions: [
eplgTb@eset.com] - C:\Program Files\ESET\ESET Smart Security\Mozilla Thunderbird
FF Extension: ESET Smart Security Extension - C:\Program Files\ESET\ESET Smart Security\Mozilla Thunderbird [2013-11-09] [not signed]
Chrome:
=======
CHR HomePage: Default -> hxxps://
www.icloud.com/
CHR StartupUrls: Default -> "hxxp://
www.icloud.com/"
CHR Session Restore: Default -> is enabled.
CHR Profile: C:\Users\Damian\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (Dokumenty Google) - C:\Users\Damian\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2015-02-07]
CHR Extension: (Disk Google) - C:\Users\Damian\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2015-10-21]
CHR Extension: (Advanced SystemCare Surfing Protection) - C:\Users\Damian\AppData\Local\Google\Chrome\User Data\Default\Extensions\bbmegnmpleoagolcnjnejdacakedpcgd [2014-12-13]
CHR Extension: (YouTube) - C:\Users\Damian\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2015-09-26]
CHR Extension: (Vyhledávání Google) - C:\Users\Damian\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2015-10-30]
CHR Extension: (Dokumenty Google offline) - C:\Users\Damian\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2016-03-15]
CHR Extension: (VLC) - C:\Users\Damian\AppData\Local\Google\Chrome\User Data\Default\Extensions\hhafecgfkakfbhlbjffclfaomoliicpm [2015-05-10]
CHR Extension: (Skype) - C:\Users\Damian\AppData\Local\Google\Chrome\User Data\Default\Extensions\lifbcibllhkdhoafpjfnlhfpfgnpldfl [2016-05-23]
CHR Extension: (Platby Internetového obchodu Chrome) - C:\Users\Damian\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2016-04-02]
CHR Extension: (Gmail) - C:\Users\Damian\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2015-03-30]
CHR HKLM-x32\...\Chrome\Extension: [lifbcibllhkdhoafpjfnlhfpfgnpldfl] - C:\Program Files (x86)\Skype\Toolbars\ChromeExtension\skype_chrome_extension.crx [2016-05-25]
==================== Services (Whitelisted) ========================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R2 AdvancedSystemCareService9; C:\Program Files (x86)\IObit\Advanced SystemCare\ASCService.exe [827680 2015-11-04] (IObit)
R2 Apple Mobile Device Service; C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe [83768 2016-03-02] (Apple Inc.)
S3 AppleChargerSrv; C:\Windows\System32\AppleChargerSrv.exe [31272 2010-04-06] ()
R2 c2cautoupdatesvc; C:\Program Files (x86)\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe [1364096 2016-05-25] (Microsoft Corporation)
R2 c2cpnrsvc; C:\Program Files (x86)\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe [1687680 2016-05-25] (Microsoft Corporation)
R2 ekrn; C:\Program Files\ESET\ESET Smart Security\x86\ekrn.exe [1337240 2013-08-19] (ESET)
R2 FreeSSHDService; C:\Program Files (x86)\freeSSHd\FreeSSHDService.exe [1513072 2015-02-02] ()
S3 IDriverT; C:\Program Files (x86)\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe [69632 2005-04-04] (Macrovision Corporation) [File not signed]
S2 LiveUpdateSvc; C:\Program Files (x86)\IObit\LiveUpdate\LiveUpdate.exe [2934048 2015-10-09] (IObit)
R2 MSSQL$SQLEXPRESS; C:\Program Files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Binn\sqlservr.exe [57617752 2009-03-30] (Microsoft Corporation)
S3 SilverSHielD; C:\Program Files\Extenua\SilverSHielD\SilverSHielDSvc.exe [10889712 2015-03-10] (Extenua, Inc.)
R2 Smart TimeLock; C:\Program Files (x86)\GIGABYTE\Smart6\Timelock\TimeMgmtDaemon.exe [114688 2009-10-13] (Gigabyte Technology CO., LTD.) [File not signed]
S4 SQLAgent$SQLEXPRESS; C:\Program Files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Binn\SQLAGENT.EXE [427880 2009-03-30] (Microsoft Corporation)
S3 SwitchBoard; C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [517096 2010-02-19] (Adobe Systems Incorporated) [File not signed]
S3 TeamViewer; C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe [5702416 2015-09-11] (TeamViewer GmbH)
S3 Update service; C:\Program Files (x86)\Popcorn Time\Updater.exe [339968 2015-07-17] (Popcorn Time) [File not signed]
R2 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2013-05-27] (Microsoft Corporation)
===================== Drivers (Whitelisted) ==========================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R1 AppleCharger; C:\Windows\System32\DRIVERS\AppleCharger.sys [21104 2011-01-10] ()
S3 BRDriver64; no ImagePath
R1 dtsoftbus01; C:\Windows\System32\DRIVERS\dtsoftbus01.sys [283200 2013-11-10] (DT Soft Ltd)
R1 eamonm; C:\Windows\System32\DRIVERS\eamonm.sys [239320 2013-08-20] (ESET)
S3 ebdrv; C:\Windows\system32\DRIVERS\evbda.sys [3286016 2009-06-10] (Broadcom Corporation)
U5 edevmon; C:\Windows\System32\Drivers\edevmon.sys [239296 2013-08-26] (ESET)
R1 ehdrv; C:\Windows\System32\DRIVERS\ehdrv.sys [168256 2013-08-20] (ESET)
R2 epfw; C:\Windows\System32\DRIVERS\epfw.sys [220232 2013-08-20] (ESET)
R1 EpfwLWF; C:\Windows\System32\DRIVERS\EpfwLWF.sys [44120 2013-08-20] (ESET)
R0 epfwwfp; C:\Windows\System32\DRIVERS\epfwwfp.sys [62136 2013-08-20] (ESET)
S3 epmntdrv; C:\Windows\system32\epmntdrv.sys [16776 2011-03-24] () [File not signed]
S3 epmntdrv; C:\Windows\SysWOW64\epmntdrv.sys [14216 2011-03-24] () [File not signed]
S3 EuGdiDrv; C:\Windows\system32\EuGdiDrv.sys [9096 2011-03-24] () [File not signed]
S3 EuGdiDrv; C:\Windows\SysWOW64\EuGdiDrv.sys [8456 2011-03-24] () [File not signed]
S3 GVTDrv64; C:\Windows\GVTDrv64.sys [30528 2014-12-31] ()
R1 HWiNFO32; C:\Windows\SysWOW64\drivers\HWiNFO64A.SYS [26528 2015-12-30] (REALiX(tm))
R3 SaiMini; C:\Windows\System32\DRIVERS\SaiMini.sys [25120 2013-04-16] (Saitek)
R3 SaiNtBus; C:\Windows\System32\drivers\SaiBus.sys [51560 2014-06-13] (Saitek)
S3 SWDUMon; C:\Windows\System32\DRIVERS\SWDUMon.sys [16056 2016-01-19] (SlimWare Utilities, Inc.)
R3 _hid_0738_1715; C:\Windows\System32\DRIVERS\_hid_0738_1715.sys [179904 2014-06-13] (Saitek)
R3 _usb_0738_1715; C:\Windows\System32\DRIVERS\_usb_0738_1715.sys [46528 2014-06-13] (Saitek)
S3 cpuz130; \??\C:\Users\Damian\AppData\Local\Temp\cpuz130\cpuz_x64.sys [X]
S3 Synth3dVsc; System32\drivers\synth3dvsc.sys [X]
S3 tsusbhub; system32\drivers\tsusbhub.sys [X]
S3 VGPU; System32\drivers\rdvgkmd.sys [X]
S3 xhunter1; \??\C:\Windows\xhunter1.sys [X]
==================== NetSvcs (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
==================== One Month Created files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2016-06-23 20:22 - 2016-06-23 20:22 - 00023604 _____ C:\Users\Damian\Desktop\FRST.txt
2016-06-23 20:21 - 2016-06-23 20:21 - 00112640 _____ (forum.viry.cz) C:\Users\Damian\Desktop\FRSTLauncher.exe
2016-06-23 20:21 - 2016-06-23 20:21 - 00029696 _____ C:\Users\Damian\AppData\Local\MSGBOX.EXE
2016-06-23 20:21 - 2016-06-23 20:21 - 00015327 _____ C:\Users\Damian\Desktop\LM.bat
2016-06-23 20:19 - 2016-06-23 20:22 - 00000000 ____D C:\FRST
2016-06-23 20:19 - 2016-06-23 20:19 - 00112640 _____ (forum.viry.cz) C:\Users\Damian\Downloads\Nepotvrzeno 525938.crdownload
2016-06-23 20:19 - 2016-06-23 20:19 - 00112640 _____ (forum.viry.cz) C:\Users\Damian\Desktop\Nepotvrzeno 687352.crdownload
2016-06-23 20:18 - 2016-06-23 20:18 - 02387456 _____ (Farbar) C:\Users\Damian\Desktop\FRST64.exe
2016-06-23 17:52 - 2016-06-23 17:52 - 110019552 _____ (Zenimax Media Inc) C:\Users\Damian\Downloads\Install_ESO.exe
2016-06-23 17:50 - 2016-06-23 17:50 - 00000028 _____ C:\Windows\OutLog.txt
2016-06-23 01:53 - 2016-06-23 01:53 - 00046513 _____ C:\Users\Damian\Downloads\Fargo-S02E05(0000262170).srt
2016-06-22 01:39 - 2016-06-22 01:39 - 00043773 _____ C:\Users\Damian\Downloads\Fargo-S02E04(0000261858).srt
2016-06-20 22:02 - 2016-06-20 22:02 - 00000000 ____D C:\Users\Damian\Downloads\pivo
2016-06-20 01:01 - 2016-06-20 01:01 - 00047228 _____ C:\Users\Damian\Downloads\Fargo-S02E03(0000261483).srt
2016-06-19 23:52 - 2016-06-19 23:52 - 00041669 _____ C:\Users\Damian\Downloads\Fargo-S02E02(0000261084).srt
2016-06-19 01:48 - 2016-06-19 01:48 - 00045281 _____ C:\Users\Damian\Downloads\Fargo-S02E01(0000260672).srt
2016-06-18 21:11 - 2016-06-18 21:11 - 00000000 ____D C:\Users\Damian\Downloads\Yung Lean - Warlord (Deluxe)
2016-06-18 02:06 - 2016-06-18 02:06 - 00042021 _____ C:\Users\Damian\Downloads\Fargo-S01E10(0000238145).srt
2016-06-18 00:29 - 2016-06-18 00:29 - 00051702 _____ C:\Users\Damian\Downloads\Fargo-S01E09(0000237863).srt
2016-06-18 00:28 - 2016-06-18 00:28 - 00015173 _____ C:\Users\Damian\Downloads\[kat.cr]fargo.season.2.complete.s02.w.eng.subs.720p.hdtv.x264.mkv.ac3.5.1.ehhhh.torrent
2016-06-17 21:14 - 2016-06-17 21:14 - 00046467 _____ C:\Users\Damian\Downloads\Fargo-S01E07(0000237248) (1).srt
2016-06-17 01:22 - 2016-06-17 01:22 - 00052712 _____ C:\Users\Damian\Downloads\Fargo-S01E08(0000237525).srt
2016-06-17 00:22 - 2016-06-17 00:22 - 00046467 _____ C:\Users\Damian\Downloads\Fargo-S01E07(0000237248).srt
2016-06-16 23:26 - 2016-06-16 23:26 - 00031634 _____ C:\Users\Damian\Downloads\Fargo-S01E06(0000236923).srt
2016-06-15 23:59 - 2016-06-15 23:59 - 00049018 _____ C:\Users\Damian\Downloads\Fargo-S01E05(0000236624).srt
2016-06-15 21:55 - 2016-06-15 21:55 - 00047113 _____ C:\Users\Damian\Downloads\Fargo-S01E04(0000236364).srt
2016-06-15 21:31 - 2016-06-15 21:39 - 144788524 _____ C:\Users\Damian\Downloads\Yung-Lean---Warlord-(Deluxe).zip
2016-06-14 22:49 - 2016-06-14 22:49 - 00048491 _____ C:\Users\Damian\Downloads\Fargo-S01E03(0000235947).srt
2016-06-14 22:48 - 2016-06-14 22:48 - 00052253 _____ C:\Users\Damian\Downloads\Fargo-S01E02(0000235621).srt
2016-06-14 22:47 - 2016-06-14 22:47 - 00068623 _____ C:\Users\Damian\Downloads\Fargo-S01E01(0000235342).srt
2016-06-14 22:27 - 2016-06-14 22:27 - 00016771 _____ C:\Users\Damian\Downloads\[kat.cr]fargo.season.1.s01.complete.hdtv.x264.torrent
2016-06-14 15:17 - 2016-06-14 16:23 - 597878654 _____ C:\Users\Damian\Downloads\Hra-o-trůny-S06E08-CZ-tit.avi
2016-06-13 22:39 - 2016-06-13 22:46 - 63547161 _____ C:\Users\Damian\Downloads\Gojira---Magma-(2016).7z
2016-06-13 00:08 - 2016-06-13 00:08 - 00000000 ____D C:\ProgramData\Codemasters
2016-06-12 23:39 - 2016-06-12 23:39 - 00000371 _____ C:\Users\Public\Desktop\DiRT Rally.lnk
2016-06-12 21:35 - 2016-06-12 21:35 - 00053093 _____ C:\Users\Damian\Downloads\[kat.cr]dirt.rally.reloaded.torrent
2016-06-09 21:32 - 2016-06-09 21:32 - 00111978 _____ C:\Users\Damian\Downloads\The-Fisher-King(0000186625).srt
2016-06-09 21:26 - 2016-06-09 21:26 - 00054748 _____ C:\Users\Damian\Downloads\[kat.cr]the.fisher.king.1991.1080p.bluray.h264.aac.rarbg.torrent
2016-06-09 21:25 - 2016-06-09 21:25 - 00037830 _____ C:\Users\Damian\Downloads\[kat.cr]the.fisher.king.1991.criterion.complete.1080p.bluray.x265.hevc.10bit.aac.5.1.apekat.torrent
2016-06-07 17:02 - 2016-06-07 18:06 - 570939644 _____ C:\Users\Damian\Downloads\Hra-o-trůny-S06E07-CZ-tit.mp4
2016-06-07 00:27 - 2016-06-07 02:02 - 858844032 _____ C:\Users\Damian\Downloads\Hra.o.truny.Game.of.Thrones.S06E06.HDTV.CZ.Titulky.avi
2016-06-06 22:21 - 2016-06-06 23:22 - 547705716 _____ C:\Users\Damian\Downloads\Hra-o-truny-S06E05-720p.H265.CZ-Dabing.mkv
2016-06-06 20:51 - 2016-06-06 20:51 - 00000132 _____ C:\Users\Damian\AppData\Roaming\Adobe GIF Format CS5 Prefs
2016-06-06 19:45 - 2016-06-06 20:45 - 533065639 _____ C:\Users\Damian\Downloads\Hra-o-truny-S06E04-720p.H265.CZ-Dabing.mkv
2016-06-06 18:41 - 2016-06-06 19:38 - 506650812 _____ C:\Users\Damian\Downloads\Hra-o-truny-S06E03-720p.H265.CZ-Dabing.mkv
2016-06-06 17:26 - 2016-06-06 17:56 - 525177340 _____ C:\Users\Damian\Downloads\Hra-o-truny-S06E02-720p.H265.CZ-Dabing.mkv
2016-06-06 13:54 - 2016-06-06 14:52 - 520203731 _____ C:\Users\Damian\Downloads\Hra-o-truny-S06E01-720p.H265.Dabing-CZ.mkv
2016-06-04 00:31 - 2016-06-04 00:31 - 00071950 _____ C:\Users\Damian\Downloads\Fury.2014.DVDScr.XviD.AC3.srt
2016-06-04 00:12 - 2016-06-04 00:24 - 2193966782 _____ C:\Users\Damian\Downloads\Fury.2014.DVDScr.XviD.AC3.avi
2016-06-03 00:11 - 2016-06-03 00:11 - 00145790 _____ C:\Users\Damian\Downloads\13-Hours-The-Secret-Soldiers-of-Benghazi(0000271873).srt
2016-06-02 17:03 - 2016-06-02 17:03 - 00000000 ____D C:\Users\Damian\AppData\Roaming\gg.minion.Minion
2016-06-02 17:01 - 2016-06-02 17:02 - 52659008 _____ (Good Game Mods LLC ) C:\Users\Damian\Downloads\Minion3.0.1.exe
2016-05-29 04:03 - 2016-05-29 04:03 - 51778703 _____ C:\Users\Damian\Downloads\Doom3_dabing_PerlaGroup.rar
2016-05-28 14:14 - 2016-05-28 14:14 - 00000879 _____ C:\Users\Damian\Desktop\DOOM 3 BFG Edition.lnk
2016-05-28 14:14 - 2016-05-28 14:14 - 00000000 ____D C:\Users\Damian\AppData\Roaming\DOOM 3 BFG Edition
2016-05-28 14:14 - 2016-05-28 14:14 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\R.G. Mechanics
2016-05-28 14:02 - 2016-05-28 14:02 - 00016132 _____ C:\Users\Damian\Downloads\[kat.cr]doom.3.bfg.edition.r.g.mechanics.torrent
2016-05-28 00:38 - 2016-05-28 00:38 - 00084260 _____ C:\Users\Damian\Downloads\The-Brothers-Grimsby(0000271752).srt
2016-05-27 00:20 - 2016-05-27 00:20 - 00091317 _____ C:\Users\Damian\Downloads\The.Brothers.Grimsby.2016.1080p.WEB-DL.DD5.1.H264-RARBG.srt
2016-05-27 00:20 - 2016-05-27 00:20 - 00035132 _____ C:\Users\Damian\Downloads\the.brothers.grimsby.(2016).eng.1cd.(6636474).zip
2016-05-26 17:19 - 2016-05-26 18:47 - 794963960 _____ C:\Users\Damian\Downloads\Hotel-Transylvania-2_dvdrip_xvid_cz.avi
2016-05-26 00:01 - 2016-05-26 00:01 - 00056056 _____ C:\Users\Damian\Downloads\Kill-Command(0000271668) (1).srt
2016-05-26 00:00 - 2016-05-26 00:00 - 00056056 _____ C:\Users\Damian\Downloads\Kill-Command(0000271668).srt
2016-05-25 23:53 - 2016-05-25 23:53 - 00033660 _____ C:\Users\Damian\Downloads\the.brothers.grimsby.(2016).cze.1cd.(6637063).zip
2016-05-25 23:52 - 2016-05-25 23:52 - 00006271 _____ C:\Users\Damian\Downloads\the.brothers.grimsby.(6637063).nfo
2016-05-24 19:44 - 2016-05-24 19:44 - 00172363 _____ C:\Users\Damian\Downloads\Steve-Jobs(0000266471).srt
2016-05-24 19:42 - 2016-05-24 19:42 - 00019301 _____ C:\Users\Damian\Downloads\[kat.cr]steve.jobs.2015.720p.brrip.x264.aac.etrg.torrent
2016-05-24 19:38 - 2016-05-24 19:38 - 00058715 _____ C:\Users\Damian\Downloads\[kat.cr]the.brothers.grimsby.2016.1080p.web.dl.dd5.1.h264.rarbg.torrent
==================== One Month Modified files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2016-06-23 20:22 - 2016-05-11 00:17 - 00000952 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA1d1ab09ae507fbe.job
2016-06-23 20:22 - 2016-02-03 22:39 - 00000952 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA1d15ec357be829.job
2016-06-23 20:19 - 2015-05-14 20:13 - 00000952 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA1d08e71b9732019.job
2016-06-23 20:18 - 2015-08-28 18:13 - 00000952 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA1d0e1ac8a089453.job
2016-06-23 20:18 - 2015-07-16 16:14 - 00000952 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA1d0bfd1bcb38c43.job
2016-06-23 20:18 - 2015-02-04 07:08 - 00000952 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA1d04038a47842d8.job
2016-06-23 20:18 - 2015-02-04 07:08 - 00000948 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore1d04038a45c5600.job
2016-06-23 20:13 - 2014-06-19 02:52 - 00000952 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA1cf8b58b35ac8a0.job
2016-06-23 19:48 - 2009-07-14 06:45 - 00010336 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2016-06-23 19:48 - 2009-07-14 06:45 - 00010336 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2016-06-23 19:37 - 2015-07-04 22:51 - 00000914 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job
2016-06-23 19:24 - 2015-09-14 23:13 - 00000952 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA1d0ef3244c56b1c.job
2016-06-23 18:18 - 2015-07-16 16:14 - 00000948 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore1d0bfd1bc95f1b4.job
2016-06-23 17:52 - 2014-05-06 22:31 - 00733876 _____ C:\Windows\system32\perfh005.dat
2016-06-23 17:52 - 2014-05-06 22:31 - 00165612 _____ C:\Windows\system32\perfc005.dat
2016-06-23 17:52 - 2009-07-14 07:13 - 00925054 _____ C:\Windows\system32\PerfStringBackup.INI
2016-06-23 17:52 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\inf
2016-06-23 17:48 - 2015-09-14 23:13 - 00000948 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore1d0ef32449867a8.job
2016-06-23 17:48 - 2014-05-23 15:35 - 00000000 ____D C:\Users\Damian\AppData\Roaming\Raptr
2016-06-23 17:48 - 2013-11-08 23:27 - 00025640 _____ (Windows (R) Server 2003 DDK provider) C:\Windows\gdrv.sys
2016-06-23 17:47 - 2016-05-11 00:17 - 00000948 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore1d1ab09ae2bb924.job
2016-06-23 17:47 - 2016-02-03 22:39 - 00000948 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore1d15ec3554b086.job
2016-06-23 17:47 - 2015-12-04 18:19 - 00000948 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore1d12eaf8b10f77d.job
2016-06-23 17:47 - 2015-08-28 18:13 - 00000948 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore1d0e1ac89e29535.job
2016-06-23 17:47 - 2015-05-14 20:13 - 00000948 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore1d08e71b955ac9b.job
2016-06-23 17:47 - 2013-11-23 18:24 - 00000948 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2016-06-23 17:47 - 2009-07-14 07:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2016-06-23 02:00 - 2014-10-24 13:42 - 00000000 ____D C:\Users\Damian\AppData\Local\Adobe
2016-06-20 22:28 - 2015-09-21 19:27 - 00003348 _____ C:\Windows\System32\Tasks\ESET Windows 10 upgrade – Refresh settings
2016-06-20 18:31 - 2013-11-28 16:07 - 00000000 ____D C:\ProgramData\ProductData
2016-06-19 01:01 - 2015-05-14 17:30 - 00000892 _____ C:\Windows\Tasks\Adobe Flash Player PPAPI Notifier.job
2016-06-18 23:32 - 2013-12-20 11:56 - 00000000 ____D C:\Users\Damian\AppData\Local\Last.fm
2016-06-18 18:37 - 2015-07-04 22:51 - 00003852 _____ C:\Windows\System32\Tasks\Adobe Flash Player Updater
2016-06-18 17:01 - 2015-05-14 17:30 - 00003890 _____ C:\Windows\System32\Tasks\Adobe Flash Player PPAPI Notifier
2016-06-18 04:36 - 2014-03-11 22:32 - 00000000 ____D C:\Users\Damian\AppData\Roaming\uTorrent
2016-06-18 02:24 - 2013-11-23 18:25 - 00002195 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2016-06-18 00:28 - 2016-04-12 19:52 - 00000000 ____D C:\Users\Damian\AppData\LocalLow\uTorrent
2016-06-17 22:37 - 2013-11-15 19:14 - 00796352 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2016-06-17 22:37 - 2013-11-15 19:14 - 00142528 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2016-06-16 16:29 - 2015-02-28 21:35 - 00003848 _____ C:\Windows\System32\Tasks\Opera scheduled Autoupdate 1383946273
2016-06-16 16:29 - 2013-11-08 23:28 - 00000000 ____D C:\Program Files (x86)\Opera
2016-06-15 22:41 - 2016-03-05 21:54 - 00000000 ____D C:\Users\Damian\AppData\Local\BlackDesertOnline
2016-06-13 00:08 - 2013-11-09 00:47 - 00000000 ____D C:\Users\Damian\Documents\My Games
2016-06-12 21:23 - 2009-07-14 07:08 - 00032622 _____ C:\Windows\Tasks\SCHEDLGU.TXT
2016-06-09 21:28 - 2015-07-07 00:39 - 00000000 ____D C:\Users\Damian\Downloads\PopcornTime
2016-06-06 20:59 - 2013-11-21 03:09 - 00001456 _____ C:\Users\Damian\AppData\Local\Adobe Save for Web 12.0 Prefs
2016-06-05 17:15 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\system32\NDF
2016-06-05 17:12 - 2016-01-06 22:05 - 00002908 _____ C:\Windows\System32\Tasks\Uninstaller_SkipUac_Damian
2016-06-05 17:06 - 2014-08-14 01:15 - 00000000 ____D C:\Users\Damian\AppData\Local\ElevatedDiagnostics
2016-06-03 03:01 - 2015-09-06 17:15 - 00000000 ____D C:\Users\Damian\.junique
2016-06-02 17:03 - 2015-09-06 17:15 - 00000668 _____ C:\Users\Damian\Documents\Minion.lnk
2016-06-02 17:03 - 2015-09-06 17:15 - 00000000 ____D C:\Users\Damian\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\ZAM Network LLC
2016-06-02 17:03 - 2015-09-06 17:15 - 00000000 ____D C:\Users\Damian\AppData\Local\Minion
2016-06-02 17:03 - 2015-09-06 17:15 - 00000000 ____D C:\Users\Damian\.minion
2016-05-30 18:39 - 2014-01-11 10:42 - 00000000 ____D C:\Users\Damian\AppData\Roaming\Awesomium
2016-05-29 12:54 - 2016-01-16 23:02 - 00000000 ____D C:\Users\Damian\AppData\Roaming\VOPackage
2016-05-29 12:37 - 2016-01-16 23:02 - 00000000 ____D C:\Program Files (x86)\00000000-1452978134-0000-0000-50E5495778AE
2016-05-28 14:20 - 2015-08-08 19:02 - 00000000 ____D C:\Users\Damian\AppData\Roaming\OBS
2016-05-28 14:20 - 2015-08-08 19:02 - 00000000 ____D C:\Program Files (x86)\OBS
2016-05-26 19:33 - 2014-02-05 14:14 - 00000000 ___RD C:\Program Files (x86)\Skype
==================== Files in the root of some directories =======
2015-06-23 17:51 - 2015-06-23 17:51 - 0000132 _____ () C:\Users\Damian\AppData\Roaming\Adobe Formát BMP CS6 – předvolby
2016-06-06 20:51 - 2016-06-06 20:51 - 0000132 _____ () C:\Users\Damian\AppData\Roaming\Adobe GIF Format CS5 Prefs
2016-04-01 22:57 - 2016-04-01 22:57 - 0000132 _____ () C:\Users\Damian\AppData\Roaming\Adobe IllExport Filter CS5 Prefs
2013-11-26 03:36 - 2015-12-17 19:06 - 0000132 _____ () C:\Users\Damian\AppData\Roaming\Adobe PNG Format CS5 Prefs
2016-04-01 21:53 - 2016-04-01 22:10 - 0000034 _____ () C:\Users\Damian\AppData\Roaming\AdobeWLCMCache.dat
2015-08-08 18:19 - 2015-08-08 18:19 - 0000040 _____ () C:\Users\Damian\AppData\Roaming\Camdata.ini
2015-08-08 18:19 - 2015-08-08 18:19 - 0000408 _____ () C:\Users\Damian\AppData\Roaming\CamLayout.ini
2015-08-08 18:19 - 2015-08-08 18:19 - 0000408 _____ () C:\Users\Damian\AppData\Roaming\CamShapes.ini
2015-08-08 18:19 - 2015-08-08 18:19 - 0004525 _____ () C:\Users\Damian\AppData\Roaming\CamStudio.cfg
2014-06-18 21:15 - 2014-06-18 21:15 - 0000024 _____ () C:\Users\Damian\AppData\Roaming\temp.ini
2013-11-21 03:09 - 2016-06-06 20:59 - 0001456 _____ () C:\Users\Damian\AppData\Local\Adobe Save for Web 12.0 Prefs
2014-05-28 15:45 - 2014-05-28 18:49 - 0007168 _____ () C:\Users\Damian\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2016-06-23 20:21 - 2016-06-23 20:21 - 0029696 _____ () C:\Users\Damian\AppData\Local\MSGBOX.EXE
2015-07-12 00:54 - 2015-08-30 23:34 - 22235535 _____ () C:\Users\Damian\AppData\Local\package.nw.new
2015-05-10 10:07 - 2015-05-10 10:07 - 0000600 _____ () C:\Users\Damian\AppData\Local\PUTTY.RND
2016-04-01 23:57 - 2016-04-01 23:57 - 0000860 _____ () C:\Users\Damian\AppData\Local\recently-used.xbel
2014-05-24 02:35 - 2015-08-29 19:50 - 0007627 _____ () C:\Users\Damian\AppData\Local\Resmon.ResmonCfg
2014-02-20 18:20 - 2014-02-20 18:20 - 0002221 _____ () C:\Users\Damian\AppData\Local\WiDiSetupLog.20140220.172029.txt
2014-02-20 18:23 - 2014-02-20 18:23 - 0005735 _____ () C:\Users\Damian\AppData\Local\WiDiSetupLog.20140220.172324.txt
2014-02-20 18:23 - 2014-02-20 18:24 - 0005735 _____ () C:\Users\Damian\AppData\Local\WiDiSetupLog.20140220.172350.txt
Files to move or delete:
====================
C:\ProgramData\C__Users_Damian_AppData_Local_Temp_Rar$EXa0.271_Hide IP Easy 5.0.5.2 Full + crack [TrT-TcT]_Crack_HideIPEasy.exe
C:\ProgramData\D__Torrent_Hide IP Easy 5.3.1.2+Crack-XenoCoder_Crack_HideIPEasy.exe
Some files in TEMP:
====================
C:\Users\Damian\AppData\Local\Temp\45f787eda638464c74f1fd404380489f.dll
C:\Users\Damian\AppData\Local\Temp\6699d3ee8dd9cf775caae782c8f44f03.dll
C:\Users\Damian\AppData\Local\Temp\befcfgafcb.exe
C:\Users\Damian\AppData\Local\Temp\jre-8u91-windows-au.exe
C:\Users\Damian\AppData\Local\Temp\playstv_patch.exe
==================== Bamital & volsnap =================
(There is no automatic fix for files that do not pass verification.)
C:\Windows\system32\winlogon.exe => File is digitally signed
C:\Windows\system32\wininit.exe => File is digitally signed
C:\Windows\SysWOW64\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\system32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\system32\services.exe => File is digitally signed
C:\Windows\system32\User32.dll
[2016-01-17 02:10] - [2016-01-17 06:20] - 1008640 ____A (Microsoft Corporation) 2C353B6CE0C8D03225CAA2AF33B68D79
C:\Windows\SysWOW64\User32.dll
[2016-01-17 02:10] - [2016-01-17 06:20] - 0833024 ____A (Microsoft Corporation) 861C4346F9281DC0380DE72C8D55D6BE
C:\Windows\system32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\system32\rpcss.dll => File is digitally signed
C:\Windows\system32\dnsapi.dll => File is digitally signed
C:\Windows\SysWOW64\dnsapi.dll => File is digitally signed
C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed
LastRegBack: 2016-06-22 02:39
==================== End of FRST.txt ============================