RUDY! - Kontrola logu určite tam niečo je...
Napsal: 02 črc 2016 13:28
Zdravím ťa prosím o pozretie logu norton internet security 2016 detekoval niečo v D:/2a7638ff4ebf9aed1decdf/Setup.exe a omnoho viac a hned po preisntalci bol pridany 127.0.0.0/255.0.0.0 IP
Rudy ak ti niekto bude písať že nech môj log neriešíš tak su to ty hackeri....

FRST
Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 02-07-2016
Ran by L4k0 (administrator) on L4K0-PC (02-07-2016 14:10:13)
Running from C:\Users\L4k0\Desktop
Loaded Profiles: L4k0 (Available Profiles: L4k0)
Platform: Windows 7 Home Premium Service Pack 1 (X64) Language: Slovenčina (Slovensko)
Internet Explorer Version 8 (Default browser: Chrome)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/33 ... scan-tool/
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(AMD) C:\Windows\System32\atiesrxx.exe
(AMD) C:\Windows\System32\atieclxx.exe
(Symantec Corporation) C:\Program Files (x86)\Norton Internet Security\Engine\21.0.0.100\NIS.exe
(Symantec Corporation) C:\Program Files (x86)\Norton Internet Security\Engine\21.0.0.100\NIS.exe
(Advanced Micro Devices, Inc.) C:\Program Files\AMD\CNext\CNext\RadeonSettings.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Microsoft Corporation) C:\Windows\System32\msiexec.exe
(Softros Systems, Inc.) C:\Program Files\Softros Systems\Process Blocker\Process Blocker.exe
(Softros Systems, Inc.) C:\Program Files\Softros Systems\Process Blocker\Tray Informer.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
==================== Registry (Whitelisted) ===========================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [StartCN] => C:\Program Files\AMD\CNext\CNext\RadeonSettings.exe [5006536 2016-03-21] (Advanced Micro Devices, Inc.)
HKLM\...\AppCertDlls: [ProcessBlocker] -> C:\Program Files\Softros Systems\Process Blocker\HelperLib.dll [114176 2015-04-10] (Softros Systems, inc.)
HKLM\...\AppCertDlls: [ProcessBlocker86] -> C:\Program Files\Softros Systems\Process Blocker\HelperLib86.dll [95744 2015-04-10] (Softros Systems, inc.)
Startup: C:\Users\L4k0\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Norton Internet Security.lnk [2016-07-02]
ShortcutTarget: Norton Internet Security.lnk -> C:\Program Files (x86)\Norton Internet Security\Engine64\21.0.0.100\uiStub.exe (Symantec Corporation)
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
Tcpip\Parameters: [DhcpNameServer] 4.2.2.1 4.2.2.2
Tcpip\..\Interfaces\{021C0871-D141-4C07-8E02-BDC2CE799FB0}: [DhcpNameServer] 4.2.2.1 4.2.2.2
Internet Explorer:
==================
HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page =
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL =
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL =
HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Local Page =
BHO: No Name -> {6C680BAE-655C-4E3D-8FC4-E6A520C3D928} -> No File
BHO-x32: Norton Identity Protection -> {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} -> C:\Program Files (x86)\Norton Internet Security\Engine\21.0.0.100\coIEPlg.dll [2013-08-15] (Symantec Corporation)
BHO-x32: No Name -> {6C680BAE-655C-4E3D-8FC4-E6A520C3D928} -> No File
BHO-x32: Norton Vulnerability Protection -> {6D53EC84-6AAE-4787-AEEE-F4628F01010C} -> C:\Program Files (x86)\Norton Internet Security\Engine\21.0.0.100\IPS\IPSBHO.DLL [2013-08-06] (Symantec Corporation)
Toolbar: HKLM-x32 - Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files (x86)\Norton Internet Security\Engine\21.0.0.100\coIEPlg.dll [2013-08-15] (Symantec Corporation)
Filter: deflate - {8f6b0360-b80d-11d0-a9b3-006097942311} - C:\Windows\system32\urlmon.dll [2010-11-21] (Microsoft Corporation)
Filter-x32: deflate - {8f6b0360-b80d-11d0-a9b3-006097942311} - C:\Windows\SysWOW64\urlmon.dll [2010-11-21] (Microsoft Corporation)
Filter: gzip - {8f6b0360-b80d-11d0-a9b3-006097942311} - C:\Windows\system32\urlmon.dll [2010-11-21] (Microsoft Corporation)
Filter-x32: gzip - {8f6b0360-b80d-11d0-a9b3-006097942311} - C:\Windows\SysWOW64\urlmon.dll [2010-11-21] (Microsoft Corporation)
Filter: video/mp4 - {20C75730-7C25-476B-95DC-C65810F9E489} - C:\Program Files\AMD\SteadyVideo\VideoMIMEFilter.dll [2011-06-08] (Advanced Micro Devices)
Filter-x32: video/mp4 - {20C75730-7C25-476B-95DC-C65810F9E489} - C:\Program Files (x86)\amd\SteadyVideo\VideoMIMEFilter.dll [2011-06-08] (Advanced Micro Devices)
Filter: video/x-flv - {20C75730-7C25-476B-95DC-C65810F9E489} - C:\Program Files\AMD\SteadyVideo\VideoMIMEFilter.dll [2011-06-08] (Advanced Micro Devices)
Filter-x32: video/x-flv - {20C75730-7C25-476B-95DC-C65810F9E489} - C:\Program Files (x86)\amd\SteadyVideo\VideoMIMEFilter.dll [2011-06-08] (Advanced Micro Devices)
FireFox:
========
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.21.115\npGoogleUpdate3.dll [2016-07-02] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.21.115\npGoogleUpdate3.dll [2016-07-02] (Google Inc.)
FF HKLM-x32\...\Firefox\Extensions: [{BBDA0591-3099-440a-AA10-41764D9DB4DB}] - C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_21.0.0.100\IPSFFPlgn
FF Extension: Norton Vulnerability Protection - C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_21.0.0.100\IPSFFPlgn [2016-07-02] [not signed]
FF HKLM-x32\...\Firefox\Extensions: [{2D3F3651-74B9-4795-BDEC-6DA2F431CB62}] - C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_21.0.0.100\coFFPlgn
FF Extension: Norton Toolbar - C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_21.0.0.100\coFFPlgn [2016-07-02] [not signed]
Chrome:
=======
CHR Profile: C:\Users\L4k0\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (Disk Google) - C:\Users\L4k0\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2016-07-02]
CHR Extension: (YouTube) - C:\Users\L4k0\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2016-07-02]
CHR Extension: (Hľadať v Google) - C:\Users\L4k0\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2016-07-02]
CHR Extension: (Norton Identity Protection) - C:\Users\L4k0\AppData\Local\Google\Chrome\User Data\Default\Extensions\mkfokfffehpeedafpekjeddnmnjhmcmk [2016-07-02]
CHR Extension: (Gmail) - C:\Users\L4k0\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2016-07-02]
CHR HKLM-x32\...\Chrome\Extension: [mkfokfffehpeedafpekjeddnmnjhmcmk] - C:\Program Files (x86)\Norton Internet Security\Engine\21.0.0.100\Exts\Chrome.crx [2016-07-02]
==================== Services (Whitelisted) ========================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R2 NIS; C:\Program Files (x86)\Norton Internet Security\Engine\21.0.0.100\NIS.exe [275696 2013-08-16] (Symantec Corporation)
R2 Process Blocker; C:\Program Files\Softros Systems\Process Blocker\Process Blocker.exe [2219344 2015-04-10] (Softros Systems, Inc.)
S3 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2009-07-14] (Microsoft Corporation)
===================== Drivers (Whitelisted) ==========================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R1 BHDrvx64; C:\Program Files (x86)\Norton Internet Security\NortonData\21.0.0.100\Definitions\BASHDefs\20130814.001\BHDrvx64.sys [1525336 2013-08-13] (Symantec Corporation)
R1 ccSet_NIS; C:\Windows\system32\drivers\NISx64\1500000.064\ccSetx64.sys [150104 2013-07-30] (Symantec Corporation)
S3 ebdrv; C:\Windows\system32\drivers\evbda.sys [3286016 2009-06-10] (Broadcom Corporation)
R1 eeCtrl; C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\eeCtrl64.sys [497392 2016-07-02] (Symantec Corporation)
U3 EraserUtilDrv11521; C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\EraserUtilDrv11521.sys [156912 2016-07-02] (Symantec Corporation)
R1 IDSVia64; C:\Program Files (x86)\Norton Internet Security\NortonData\21.0.0.100\Definitions\IPSDefs\20130805.011\IDSVia64.sys [520280 2013-08-06] (Symantec Corporation)
R3 NAVENG; C:\Program Files (x86)\Norton Internet Security\NortonData\21.0.0.100\Definitions\VirusDefs\20160701.036\ENG64.SYS [138456 2016-07-02] (Symantec Corporation)
R3 NAVEX15; C:\Program Files (x86)\Norton Internet Security\NortonData\21.0.0.100\Definitions\VirusDefs\20160701.036\EX64.SYS [2148056 2016-07-02] (Symantec Corporation)
R3 SRTSP; C:\Windows\system32\drivers\NISx64\1500000.064\SRTSP64.SYS [854616 2013-07-31] (Symantec Corporation)
R1 SRTSPX; C:\Windows\system32\drivers\NISx64\1500000.064\SRTSPX64.SYS [36952 2013-07-31] (Symantec Corporation)
R0 SymDS; C:\Windows\System32\drivers\NISx64\1500000.064\SYMDS64.SYS [493656 2013-08-01] (Symantec Corporation)
R0 SymEFA; C:\Windows\System32\drivers\NISx64\1500000.064\SYMEFA64.SYS [1147480 2013-08-05] (Symantec Corporation)
R3 SymEvent; C:\Windows\system32\Drivers\SYMEVENT64x86.SYS [177752 2016-07-02] (Symantec Corporation)
R1 SymIRON; C:\Windows\system32\drivers\NISx64\1500000.064\Ironx64.SYS [264280 2013-07-31] (Symantec Corporation)
R1 SymNetS; C:\Windows\system32\drivers\NISx64\1500000.064\SYMNETS.SYS [590424 2013-07-31] (Symantec Corporation)
==================== NetSvcs (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
==================== One Month Created files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2016-07-02 14:10 - 2016-07-02 14:10 - 00010913 _____ C:\Users\L4k0\Desktop\FRST.txt
2016-07-02 14:10 - 2016-07-02 14:10 - 00000000 ____D C:\FRST
2016-07-02 14:09 - 2016-07-02 14:09 - 02390016 _____ (Farbar) C:\Users\L4k0\Desktop\FRST64.exe
2016-07-02 14:07 - 2016-07-02 14:07 - 00001296 _____ C:\Users\L4k0\Desktop\fgdf.txt
2016-07-02 14:00 - 2016-07-02 14:00 - 00000000 ____D C:\Users\L4k0\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Process Blocker
2016-07-02 14:00 - 2016-07-02 14:00 - 00000000 ____D C:\Program Files\Softros Systems
2016-07-02 13:52 - 2016-07-02 13:52 - 00000000 ____D C:\Users\L4k0\AppData\Local\AMD
2016-07-02 13:51 - 2016-07-02 13:51 - 00000000 _____ C:\Windows\ativpsrm.bin
2016-07-02 13:50 - 2016-07-02 13:50 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Vulkan 1.0.3.1
2016-07-02 13:50 - 2016-07-02 13:50 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AMD Radeon Settings
2016-07-02 13:50 - 2016-07-02 13:50 - 00000000 ____D C:\Program Files (x86)\VulkanRT
2016-07-02 13:50 - 2016-07-02 13:50 - 00000000 ____D C:\Program Files (x86)\AMD
2016-07-02 13:50 - 2016-02-16 01:27 - 00125720 _____ C:\Windows\SysWOW64\vulkan-1.dll
2016-07-02 13:50 - 2016-02-16 01:26 - 00126232 _____ C:\Windows\system32\vulkan-1.dll
2016-07-02 13:50 - 2016-02-16 01:25 - 00045848 _____ C:\Windows\system32\vulkaninfo.exe
2016-07-02 13:50 - 2016-02-16 01:25 - 00042264 _____ C:\Windows\SysWOW64\vulkaninfo.exe
2016-07-02 13:49 - 2016-07-02 13:50 - 00000000 ____D C:\ProgramData\Package Cache
2016-07-02 13:49 - 2016-07-02 13:49 - 00000000 ____D C:\Program Files\Common Files\ATI Technologies
2016-07-02 13:47 - 2016-07-02 13:47 - 00749404 _____ C:\Windows\SysWOW64\PerfStringBackup.INI
2016-07-02 13:45 - 2016-07-02 13:50 - 00000000 ____D C:\Program Files\AMD
2016-07-02 13:43 - 2016-07-02 13:43 - 00000043 _____ C:\Users\L4k0\Desktop\Nový textový dokument.txt
2016-07-02 13:13 - 2016-07-02 12:19 - 00000000 ____D C:\Windows\Panther
2016-07-02 13:10 - 2016-07-02 13:10 - 00002255 _____ C:\Users\Public\Desktop\Google Chrome.lnk
2016-07-02 13:10 - 2016-07-02 13:10 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome
2016-07-02 13:09 - 2016-07-02 13:52 - 00000928 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2016-07-02 13:09 - 2016-07-02 13:14 - 00000932 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2016-07-02 13:09 - 2016-07-02 13:10 - 00000000 ____D C:\Users\L4k0\AppData\Local\Google
2016-07-02 13:09 - 2016-07-02 13:09 - 00003928 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA
2016-07-02 13:09 - 2016-07-02 13:09 - 00003676 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore
2016-07-02 13:09 - 2016-07-02 13:09 - 00000000 ____D C:\Program Files (x86)\Google
2016-07-02 12:34 - 2016-07-02 12:34 - 00000000 ____D C:\Windows\System32\Tasks\Norton Internet Security
2016-07-02 12:30 - 2016-07-02 12:30 - 00177752 _____ (Symantec Corporation) C:\Windows\system32\Drivers\SYMEVENT64x86.SYS
2016-07-02 12:30 - 2016-07-02 12:30 - 00008222 _____ C:\Windows\system32\Drivers\SYMEVENT64x86.CAT
2016-07-02 12:30 - 2016-07-02 12:30 - 00003236 _____ C:\Windows\System32\Tasks\Norton WSC Integration
2016-07-02 12:30 - 2016-07-02 12:30 - 00002584 _____ C:\Users\Public\Desktop\Norton Internet Security.lnk
2016-07-02 12:30 - 2016-07-02 12:30 - 00000000 ____D C:\Program Files\Common Files\Symantec Shared
2016-07-02 12:29 - 2016-07-02 12:31 - 00000000 ____D C:\ProgramData\Norton
2016-07-02 12:29 - 2016-07-02 12:30 - 00000000 ___RD C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Norton Internet Security
2016-07-02 12:29 - 2016-07-02 12:29 - 00000000 ____D C:\Windows\system32\Drivers\NISx64
2016-07-02 12:29 - 2016-07-02 12:29 - 00000000 ____D C:\ProgramData\NortonInstaller
2016-07-02 12:29 - 2016-07-02 12:29 - 00000000 ____D C:\Program Files (x86)\NortonInstaller
2016-07-02 12:29 - 2016-07-02 12:29 - 00000000 ____D C:\Program Files (x86)\Norton Internet Security
2016-07-02 12:21 - 2016-07-02 12:21 - 00057560 _____ C:\Users\L4k0\AppData\Local\GDIPFONTCACHEV1.DAT
2016-07-02 12:19 - 2016-07-02 12:19 - 00000020 ___SH C:\Users\L4k0\ntuser.ini
2016-07-02 12:19 - 2016-07-02 12:19 - 00000000 ____D C:\Users\L4k0\AppData\Local\VirtualStore
2016-07-02 12:19 - 2016-07-02 12:19 - 00000000 ____D C:\Users\L4k0
2016-07-02 12:19 - 2010-11-21 17:10 - 00000000 ____D C:\Users\L4k0\AppData\Roaming\Media Center Programs
2016-07-02 12:17 - 2016-07-02 12:17 - 00001345 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Media Center.lnk
2016-07-02 12:17 - 2016-07-02 12:17 - 00001326 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows DVD Maker.lnk
2016-07-02 12:15 - 2016-07-02 12:15 - 00000000 ____H C:\Windows\system32\Drivers\Msft_User_WpdFs_01_09_00.Wdf
==================== One Month Modified files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2016-07-02 13:56 - 2009-07-14 07:13 - 00781298 _____ C:\Windows\system32\PerfStringBackup.INI
2016-07-02 13:56 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\inf
2016-07-02 13:51 - 2009-07-14 07:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2016-07-02 13:51 - 2009-07-14 06:45 - 00016640 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2016-07-02 13:51 - 2009-07-14 06:45 - 00016640 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2016-07-02 13:27 - 2009-07-14 05:20 - 00000000 __RHD C:\Users\Public\Libraries
2016-07-02 13:12 - 2009-07-14 07:32 - 00028672 _____ C:\Windows\system32\config\BCD-Template
2016-07-02 13:03 - 2009-07-14 07:32 - 00000000 ___RD C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Games
2016-07-02 13:03 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\PolicyDefinitions
2016-07-02 12:18 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\rescache
2016-07-02 12:17 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\system32\sysprep
2016-07-02 12:14 - 2009-07-14 06:45 - 00274736 _____ C:\Windows\system32\FNTCACHE.DAT
Some files in TEMP:
====================
C:\Users\L4k0\AppData\Local\Temp\MSIAFTERBURNERSETUP.EXE
C:\Users\L4k0\AppData\Local\Temp\SETUP_AFTERBURNER.EXE
C:\Users\L4k0\AppData\Local\Temp\vcredist_x86.exe
==================== Bamital & volsnap =================
(There is no automatic fix for files that do not pass verification.)
C:\Windows\system32\winlogon.exe => File is digitally signed
C:\Windows\system32\wininit.exe => File is digitally signed
C:\Windows\SysWOW64\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\system32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\system32\services.exe => File is digitally signed
C:\Windows\system32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\system32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\system32\rpcss.dll => File is digitally signed
C:\Windows\system32\dnsapi.dll => File is digitally signed
C:\Windows\SysWOW64\dnsapi.dll => File is digitally signed
C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed
LastRegBack: 2016-07-02 12:14
==================== End of FRST.txt ============================
AUDITION
Additional scan result of Farbar Recovery Scan Tool (x64) Version: 02-07-2016
Ran by L4k0 (2016-07-02 14:10:36)
Running from C:\Users\L4k0\Desktop
Windows 7 Home Premium Service Pack 1 (X64) (2016-07-02 10:19:24)
Boot Mode: Normal
==========================================================
==================== Accounts: =============================
Administrator (S-1-5-21-3446584074-721549401-2035689353-500 - Administrator - Disabled)
Guest (S-1-5-21-3446584074-721549401-2035689353-501 - Limited - Disabled)
HomeGroupUser$ (S-1-5-21-3446584074-721549401-2035689353-1002 - Limited - Enabled)
L4k0 (S-1-5-21-3446584074-721549401-2035689353-1000 - Administrator - Enabled) => C:\Users\L4k0
==================== Security Center ========================
(If an entry is included in the fixlist, it will be removed.)
AV: Norton Internet Security (Enabled - Up to date) {63DF5164-9100-186D-2187-8DC619EFD8BF}
AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: Norton Internet Security (Enabled - Up to date) {D8BEB080-B73A-17E3-1B37-B6B462689202}
FW: Norton Internet Security (Enabled) {5BE4D041-DB6F-1935-0AD8-24F3E73C9FC4}
==================== Installed Programs ======================
(Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)
Catalyst Control Center Next Localization BR (Version: 2016.0321.1015.16463 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization CS (Version: 2016.0321.1015.16463 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization DA (Version: 2016.0321.1015.16463 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization DE (Version: 2016.0321.1015.16463 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization EL (Version: 2016.0321.1015.16463 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization ES (Version: 2016.0321.1015.16463 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization FI (Version: 2016.0321.1015.16463 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization FR (Version: 2016.0321.1015.16463 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization HU (Version: 2016.0321.1015.16463 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization CHS (Version: 2016.0321.1015.16463 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization CHT (Version: 2016.0321.1015.16463 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization IT (Version: 2016.0321.1015.16463 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization JA (Version: 2016.0321.1015.16463 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization KO (Version: 2016.0321.1015.16463 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization NL (Version: 2016.0321.1015.16463 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization NO (Version: 2016.0321.1015.16463 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization PL (Version: 2016.0321.1015.16463 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization RU (Version: 2016.0321.1015.16463 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization SV (Version: 2016.0321.1015.16463 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization TH (Version: 2016.0321.1015.16463 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization TR (Version: 2016.0321.1015.16463 - Advanced Micro Devices, Inc.) Hidden
Google Chrome (HKLM-x32\...\Google Chrome) (Version: 26.0.1410.40 - Google Inc.)
Google Update Helper (x32 Version: 1.3.21.115 - Google Inc.) Hidden
Microsoft .NET Framework 4.5 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.50709 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.50727 (HKLM-x32\...\{15134cb0-b767-4960-a911-f2d16ae54797}) (Version: 11.0.50727.1 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.30501 (HKLM-x32\...\{050d4fc8-5d48-4b8f-8972-47c82c46020f}) (Version: 12.0.30501.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501 (HKLM-x32\...\{f65db027-aff3-4070-886a-0d87064aabb1}) (Version: 12.0.30501.0 - Microsoft Corporation)
Norton Internet Security (HKLM-x32\...\NIS) (Version: 21.0.0.100 - Symantec Corporation)
Process Blocker 1.0.13.0 (HKLM\...\{FEC52075-E418-400D-A25C-AE7F366A9C2C}) (Version: 1.0.13.0 - Softros Systems, Inc.)
Vulkan Run Time Libraries 1.0.3.1 (HKLM\...\VulkanRT1.0.3.1) (Version: 1.0.3.1 - LunarG, Inc.)
==================== Custom CLSID (Whitelisted): ==========================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
==================== Scheduled Tasks (Whitelisted) =============
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
Task: {26A850C4-4ADA-4A3C-9145-5B8213738C5C} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2016-07-02] (Google Inc.)
Task: {5485C6C0-51BD-4027-96A7-DA06610F16D3} - System32\Tasks\Norton WSC Integration => C:\Program Files (x86)\Norton Internet Security\Engine\21.0.0.100\WSCStub.exe [2013-08-16] (Symantec Corporation)
Task: {CAD44A45-277A-4837-8D1D-F53384034BE8} - System32\Tasks\Norton Internet Security\Norton Error Processor => C:\Program Files (x86)\Norton Internet Security\Engine\21.0.0.100\SymErr.exe [2013-08-01] (Symantec Corporation)
Task: {D47083C6-EABB-4BF4-8F17-5F9273BA4842} - System32\Tasks\Norton Internet Security\Norton Error Analyzer => C:\Program Files (x86)\Norton Internet Security\Engine\21.0.0.100\SymErr.exe [2013-08-01] (Symantec Corporation)
Task: {DB8507D6-FDD7-4F27-8018-5E24C6C05222} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2016-07-02] (Google Inc.)
(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
==================== Shortcuts =============================
(The entries could be listed to be restored or removed.)
==================== Loaded Modules (Whitelisted) ==============
2015-06-25 17:34 - 2015-06-25 17:34 - 00014336 _____ () C:\Program Files\AMD\CNext\CNext\QtQuick.2\qtquick2plugin.dll
2015-06-25 17:37 - 2015-06-25 17:37 - 00739840 _____ () C:\Program Files\AMD\CNext\CNext\QtQuick\Controls\qtquickcontrolsplugin.dll
2015-06-25 17:35 - 2015-06-25 17:35 - 00014336 _____ () C:\Program Files\AMD\CNext\CNext\QtQuick\Window.2\windowplugin.dll
2015-06-25 17:38 - 2015-06-25 17:38 - 00071168 _____ () C:\Program Files\AMD\CNext\CNext\QtQuick\Layouts\qquicklayoutsplugin.dll
2015-06-25 16:53 - 2015-06-25 16:53 - 00011776 _____ () C:\Program Files\AMD\CNext\CNext\libEGL.dll
2015-06-25 16:51 - 2015-06-25 16:51 - 02013696 _____ () C:\Program Files\AMD\CNext\CNext\libGLESv2.dll
2016-07-02 13:10 - 2013-03-20 08:03 - 00598480 _____ () C:\Program Files (x86)\Google\Chrome\Application\26.0.1410.40\libglesv2.dll
2016-07-02 13:10 - 2013-03-20 08:03 - 00124368 _____ () C:\Program Files (x86)\Google\Chrome\Application\26.0.1410.40\libegl.dll
2016-07-02 13:10 - 2013-03-20 08:04 - 04050896 _____ () C:\Program Files (x86)\Google\Chrome\Application\26.0.1410.40\pdf.dll
2016-07-02 13:10 - 2013-03-20 08:04 - 00390096 _____ () C:\Program Files (x86)\Google\Chrome\Application\26.0.1410.40\ppGoogleNaClPluginChrome.dll
2016-07-02 13:10 - 2013-03-20 08:03 - 01606096 _____ () C:\Program Files (x86)\Google\Chrome\Application\26.0.1410.40\ffmpegsumo.dll
2016-07-02 13:10 - 2013-03-20 08:04 - 12662224 _____ () C:\Program Files (x86)\Google\Chrome\Application\26.0.1410.40\PepperFlash\pepflashplayer.dll
==================== Alternate Data Streams (Whitelisted) =========
(If an entry is included in the fixlist, only the ADS will be removed.)
==================== Safe Mode (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)
==================== Association (Whitelisted) ===============
(If an entry is included in the fixlist, the registry item will be restored to default or removed.)
==================== Internet Explorer trusted/restricted ===============
(If an entry is included in the fixlist, it will be removed from the registry.)
==================== Hosts content: ===============================
(If needed Hosts: directive could be included in the fixlist to reset Hosts.)
2009-07-14 04:34 - 2009-06-10 23:00 - 00000824 ____A C:\Windows\system32\Drivers\etc\hosts
==================== Other Areas ============================
(Currently there is no automatic fix for this section.)
HKU\S-1-5-21-3446584074-721549401-2035689353-1000\Control Panel\Desktop\\Wallpaper -> C:\Users\L4k0\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper.jpg
DNS Servers: 4.2.2.1 - 4.2.2.2
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
Windows Firewall is enabled.
==================== MSCONFIG/TASK MANAGER disabled items ==
(Currently there is no automatic fix for this section.)
==================== FirewallRules (Whitelisted) ===============
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
FirewallRules: [{BC2EF894-D26C-4A10-B57E-6EF57F7A9036}] => (Allow) C:\Program Files\Softros Systems\Process Blocker\Process Blocker.exe
==================== Restore Points =========================
02-07-2016 13:03:10 Inštalátor modulov systému Windows
02-07-2016 13:48:53 Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.50727
02-07-2016 13:49:07 Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.30501
02-07-2016 13:50:40 Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501
02-07-2016 14:00:37 Installed Process Blocker 1.0.13.0
==================== Faulty Device Manager Devices =============
Name:
Description:
Class Guid:
Manufacturer:
Service:
Problem: : This device is disabled. (Code 22)
Resolution: In Device Manager, click "Action", and then click "Enable Device". This starts the Enable Device wizard. Follow the instructions.
==================== Event log errors: =========================
Application errors:
==================
Error: (07/02/2016 01:56:12 PM) (Source: Microsoft-Windows-LoadPerf) (EventID: 3006) (User: NT AUTHORITY)
Description: Unable to read the performance counter strings defined for the 01B language ID. The first DWORD in the Data section contains the Win32 error code.
Error: (07/02/2016 01:56:12 PM) (Source: Microsoft-Windows-LoadPerf) (EventID: 3006) (User: NT AUTHORITY)
Description: Unable to read the performance counter strings defined for the 01B language ID. The first DWORD in the Data section contains the Win32 error code.
Error: (07/02/2016 01:53:32 PM) (Source: Microsoft-Windows-LoadPerf) (EventID: 3006) (User: NT AUTHORITY)
Description: Unable to read the performance counter strings defined for the 01B language ID. The first DWORD in the Data section contains the Win32 error code.
Error: (07/02/2016 01:53:32 PM) (Source: Microsoft-Windows-LoadPerf) (EventID: 3006) (User: NT AUTHORITY)
Description: Unable to read the performance counter strings defined for the 01B language ID. The first DWORD in the Data section contains the Win32 error code.
Error: (07/02/2016 01:53:31 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
Error: (07/02/2016 01:50:34 PM) (Source: MsiInstaller) (EventID: 11904) (User: L4k0-PC)
Description: Product: AMD Drag and Drop Transcoding -- Error 1904.Module C:\Program Files (x86)\Common Files\ATI Technologies\Multimedia\AMDMFTVideoDecoder_32.dll failed to register. HRESULT -2147024770. Contact your support personnel.
Error: (07/02/2016 01:49:22 PM) (Source: MsiInstaller) (EventID: 11723) (User: L4k0-PC)
Description: Product: AMD Install Manager -- Error 1723.There is a problem with this Windows Installer package. A DLL required for this install to complete could not be run. Contact your support personnel or package vendor. Action SetInstallDir, entry: SetInstallDir, library: C:\Windows\Installer\MSI3110.tmp
Error: (07/02/2016 01:47:17 PM) (Source: Microsoft-Windows-LoadPerf) (EventID: 3006) (User: L4k0-PC)
Description: Unable to read the performance counter strings defined for the 01B language ID. The first DWORD in the Data section contains the Win32 error code.
Error: (07/02/2016 01:47:17 PM) (Source: Microsoft-Windows-LoadPerf) (EventID: 3006) (User: L4k0-PC)
Description: Unable to read the performance counter strings defined for the 01B language ID. The first DWORD in the Data section contains the Win32 error code.
Error: (07/02/2016 01:47:16 PM) (Source: Microsoft-Windows-LoadPerf) (EventID: 3006) (User: L4k0-PC)
Description: Unable to read the performance counter strings defined for the 01B language ID. The first DWORD in the Data section contains the Win32 error code.
System errors:
=============
==================== Memory info ===========================
Processor: AMD Phenom(tm) II X4 945 Processor
Percentage of memory in use: 27%
Total physical RAM: 8191.11 MB
Available physical RAM: 5940.08 MB
Total Virtual: 16380.43 MB
Available Virtual: 13758.37 MB
==================== Drives ================================
Drive c: () (Fixed) (Total:117.19 GB) (Free:91.91 GB) NTFS
Drive d: () (Fixed) (Total:348.47 GB) (Free:348.37 GB) NTFS
==================== MBR & Partition Table ==================
========================================================
Disk: 0 (MBR Code: Windows 7 or 8) (Size: 465.8 GB) (Disk ID: 4D154D14)
Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=117.2 GB) - (Type=07 NTFS)
Partition 3: (Not Active) - (Size=348.5 GB) - (Type=07 NTFS)
==================== End of Addition.txt ============================
Rudy ak ti niekto bude písať že nech môj log neriešíš tak su to ty hackeri....

FRST
Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 02-07-2016
Ran by L4k0 (administrator) on L4K0-PC (02-07-2016 14:10:13)
Running from C:\Users\L4k0\Desktop
Loaded Profiles: L4k0 (Available Profiles: L4k0)
Platform: Windows 7 Home Premium Service Pack 1 (X64) Language: Slovenčina (Slovensko)
Internet Explorer Version 8 (Default browser: Chrome)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/33 ... scan-tool/
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(AMD) C:\Windows\System32\atiesrxx.exe
(AMD) C:\Windows\System32\atieclxx.exe
(Symantec Corporation) C:\Program Files (x86)\Norton Internet Security\Engine\21.0.0.100\NIS.exe
(Symantec Corporation) C:\Program Files (x86)\Norton Internet Security\Engine\21.0.0.100\NIS.exe
(Advanced Micro Devices, Inc.) C:\Program Files\AMD\CNext\CNext\RadeonSettings.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Microsoft Corporation) C:\Windows\System32\msiexec.exe
(Softros Systems, Inc.) C:\Program Files\Softros Systems\Process Blocker\Process Blocker.exe
(Softros Systems, Inc.) C:\Program Files\Softros Systems\Process Blocker\Tray Informer.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
==================== Registry (Whitelisted) ===========================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [StartCN] => C:\Program Files\AMD\CNext\CNext\RadeonSettings.exe [5006536 2016-03-21] (Advanced Micro Devices, Inc.)
HKLM\...\AppCertDlls: [ProcessBlocker] -> C:\Program Files\Softros Systems\Process Blocker\HelperLib.dll [114176 2015-04-10] (Softros Systems, inc.)
HKLM\...\AppCertDlls: [ProcessBlocker86] -> C:\Program Files\Softros Systems\Process Blocker\HelperLib86.dll [95744 2015-04-10] (Softros Systems, inc.)
Startup: C:\Users\L4k0\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Norton Internet Security.lnk [2016-07-02]
ShortcutTarget: Norton Internet Security.lnk -> C:\Program Files (x86)\Norton Internet Security\Engine64\21.0.0.100\uiStub.exe (Symantec Corporation)
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
Tcpip\Parameters: [DhcpNameServer] 4.2.2.1 4.2.2.2
Tcpip\..\Interfaces\{021C0871-D141-4C07-8E02-BDC2CE799FB0}: [DhcpNameServer] 4.2.2.1 4.2.2.2
Internet Explorer:
==================
HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page =
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL =
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL =
HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Local Page =
BHO: No Name -> {6C680BAE-655C-4E3D-8FC4-E6A520C3D928} -> No File
BHO-x32: Norton Identity Protection -> {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} -> C:\Program Files (x86)\Norton Internet Security\Engine\21.0.0.100\coIEPlg.dll [2013-08-15] (Symantec Corporation)
BHO-x32: No Name -> {6C680BAE-655C-4E3D-8FC4-E6A520C3D928} -> No File
BHO-x32: Norton Vulnerability Protection -> {6D53EC84-6AAE-4787-AEEE-F4628F01010C} -> C:\Program Files (x86)\Norton Internet Security\Engine\21.0.0.100\IPS\IPSBHO.DLL [2013-08-06] (Symantec Corporation)
Toolbar: HKLM-x32 - Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files (x86)\Norton Internet Security\Engine\21.0.0.100\coIEPlg.dll [2013-08-15] (Symantec Corporation)
Filter: deflate - {8f6b0360-b80d-11d0-a9b3-006097942311} - C:\Windows\system32\urlmon.dll [2010-11-21] (Microsoft Corporation)
Filter-x32: deflate - {8f6b0360-b80d-11d0-a9b3-006097942311} - C:\Windows\SysWOW64\urlmon.dll [2010-11-21] (Microsoft Corporation)
Filter: gzip - {8f6b0360-b80d-11d0-a9b3-006097942311} - C:\Windows\system32\urlmon.dll [2010-11-21] (Microsoft Corporation)
Filter-x32: gzip - {8f6b0360-b80d-11d0-a9b3-006097942311} - C:\Windows\SysWOW64\urlmon.dll [2010-11-21] (Microsoft Corporation)
Filter: video/mp4 - {20C75730-7C25-476B-95DC-C65810F9E489} - C:\Program Files\AMD\SteadyVideo\VideoMIMEFilter.dll [2011-06-08] (Advanced Micro Devices)
Filter-x32: video/mp4 - {20C75730-7C25-476B-95DC-C65810F9E489} - C:\Program Files (x86)\amd\SteadyVideo\VideoMIMEFilter.dll [2011-06-08] (Advanced Micro Devices)
Filter: video/x-flv - {20C75730-7C25-476B-95DC-C65810F9E489} - C:\Program Files\AMD\SteadyVideo\VideoMIMEFilter.dll [2011-06-08] (Advanced Micro Devices)
Filter-x32: video/x-flv - {20C75730-7C25-476B-95DC-C65810F9E489} - C:\Program Files (x86)\amd\SteadyVideo\VideoMIMEFilter.dll [2011-06-08] (Advanced Micro Devices)
FireFox:
========
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.21.115\npGoogleUpdate3.dll [2016-07-02] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.21.115\npGoogleUpdate3.dll [2016-07-02] (Google Inc.)
FF HKLM-x32\...\Firefox\Extensions: [{BBDA0591-3099-440a-AA10-41764D9DB4DB}] - C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_21.0.0.100\IPSFFPlgn
FF Extension: Norton Vulnerability Protection - C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_21.0.0.100\IPSFFPlgn [2016-07-02] [not signed]
FF HKLM-x32\...\Firefox\Extensions: [{2D3F3651-74B9-4795-BDEC-6DA2F431CB62}] - C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_21.0.0.100\coFFPlgn
FF Extension: Norton Toolbar - C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_21.0.0.100\coFFPlgn [2016-07-02] [not signed]
Chrome:
=======
CHR Profile: C:\Users\L4k0\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (Disk Google) - C:\Users\L4k0\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2016-07-02]
CHR Extension: (YouTube) - C:\Users\L4k0\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2016-07-02]
CHR Extension: (Hľadať v Google) - C:\Users\L4k0\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2016-07-02]
CHR Extension: (Norton Identity Protection) - C:\Users\L4k0\AppData\Local\Google\Chrome\User Data\Default\Extensions\mkfokfffehpeedafpekjeddnmnjhmcmk [2016-07-02]
CHR Extension: (Gmail) - C:\Users\L4k0\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2016-07-02]
CHR HKLM-x32\...\Chrome\Extension: [mkfokfffehpeedafpekjeddnmnjhmcmk] - C:\Program Files (x86)\Norton Internet Security\Engine\21.0.0.100\Exts\Chrome.crx [2016-07-02]
==================== Services (Whitelisted) ========================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R2 NIS; C:\Program Files (x86)\Norton Internet Security\Engine\21.0.0.100\NIS.exe [275696 2013-08-16] (Symantec Corporation)
R2 Process Blocker; C:\Program Files\Softros Systems\Process Blocker\Process Blocker.exe [2219344 2015-04-10] (Softros Systems, Inc.)
S3 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2009-07-14] (Microsoft Corporation)
===================== Drivers (Whitelisted) ==========================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R1 BHDrvx64; C:\Program Files (x86)\Norton Internet Security\NortonData\21.0.0.100\Definitions\BASHDefs\20130814.001\BHDrvx64.sys [1525336 2013-08-13] (Symantec Corporation)
R1 ccSet_NIS; C:\Windows\system32\drivers\NISx64\1500000.064\ccSetx64.sys [150104 2013-07-30] (Symantec Corporation)
S3 ebdrv; C:\Windows\system32\drivers\evbda.sys [3286016 2009-06-10] (Broadcom Corporation)
R1 eeCtrl; C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\eeCtrl64.sys [497392 2016-07-02] (Symantec Corporation)
U3 EraserUtilDrv11521; C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\EraserUtilDrv11521.sys [156912 2016-07-02] (Symantec Corporation)
R1 IDSVia64; C:\Program Files (x86)\Norton Internet Security\NortonData\21.0.0.100\Definitions\IPSDefs\20130805.011\IDSVia64.sys [520280 2013-08-06] (Symantec Corporation)
R3 NAVENG; C:\Program Files (x86)\Norton Internet Security\NortonData\21.0.0.100\Definitions\VirusDefs\20160701.036\ENG64.SYS [138456 2016-07-02] (Symantec Corporation)
R3 NAVEX15; C:\Program Files (x86)\Norton Internet Security\NortonData\21.0.0.100\Definitions\VirusDefs\20160701.036\EX64.SYS [2148056 2016-07-02] (Symantec Corporation)
R3 SRTSP; C:\Windows\system32\drivers\NISx64\1500000.064\SRTSP64.SYS [854616 2013-07-31] (Symantec Corporation)
R1 SRTSPX; C:\Windows\system32\drivers\NISx64\1500000.064\SRTSPX64.SYS [36952 2013-07-31] (Symantec Corporation)
R0 SymDS; C:\Windows\System32\drivers\NISx64\1500000.064\SYMDS64.SYS [493656 2013-08-01] (Symantec Corporation)
R0 SymEFA; C:\Windows\System32\drivers\NISx64\1500000.064\SYMEFA64.SYS [1147480 2013-08-05] (Symantec Corporation)
R3 SymEvent; C:\Windows\system32\Drivers\SYMEVENT64x86.SYS [177752 2016-07-02] (Symantec Corporation)
R1 SymIRON; C:\Windows\system32\drivers\NISx64\1500000.064\Ironx64.SYS [264280 2013-07-31] (Symantec Corporation)
R1 SymNetS; C:\Windows\system32\drivers\NISx64\1500000.064\SYMNETS.SYS [590424 2013-07-31] (Symantec Corporation)
==================== NetSvcs (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
==================== One Month Created files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2016-07-02 14:10 - 2016-07-02 14:10 - 00010913 _____ C:\Users\L4k0\Desktop\FRST.txt
2016-07-02 14:10 - 2016-07-02 14:10 - 00000000 ____D C:\FRST
2016-07-02 14:09 - 2016-07-02 14:09 - 02390016 _____ (Farbar) C:\Users\L4k0\Desktop\FRST64.exe
2016-07-02 14:07 - 2016-07-02 14:07 - 00001296 _____ C:\Users\L4k0\Desktop\fgdf.txt
2016-07-02 14:00 - 2016-07-02 14:00 - 00000000 ____D C:\Users\L4k0\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Process Blocker
2016-07-02 14:00 - 2016-07-02 14:00 - 00000000 ____D C:\Program Files\Softros Systems
2016-07-02 13:52 - 2016-07-02 13:52 - 00000000 ____D C:\Users\L4k0\AppData\Local\AMD
2016-07-02 13:51 - 2016-07-02 13:51 - 00000000 _____ C:\Windows\ativpsrm.bin
2016-07-02 13:50 - 2016-07-02 13:50 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Vulkan 1.0.3.1
2016-07-02 13:50 - 2016-07-02 13:50 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AMD Radeon Settings
2016-07-02 13:50 - 2016-07-02 13:50 - 00000000 ____D C:\Program Files (x86)\VulkanRT
2016-07-02 13:50 - 2016-07-02 13:50 - 00000000 ____D C:\Program Files (x86)\AMD
2016-07-02 13:50 - 2016-02-16 01:27 - 00125720 _____ C:\Windows\SysWOW64\vulkan-1.dll
2016-07-02 13:50 - 2016-02-16 01:26 - 00126232 _____ C:\Windows\system32\vulkan-1.dll
2016-07-02 13:50 - 2016-02-16 01:25 - 00045848 _____ C:\Windows\system32\vulkaninfo.exe
2016-07-02 13:50 - 2016-02-16 01:25 - 00042264 _____ C:\Windows\SysWOW64\vulkaninfo.exe
2016-07-02 13:49 - 2016-07-02 13:50 - 00000000 ____D C:\ProgramData\Package Cache
2016-07-02 13:49 - 2016-07-02 13:49 - 00000000 ____D C:\Program Files\Common Files\ATI Technologies
2016-07-02 13:47 - 2016-07-02 13:47 - 00749404 _____ C:\Windows\SysWOW64\PerfStringBackup.INI
2016-07-02 13:45 - 2016-07-02 13:50 - 00000000 ____D C:\Program Files\AMD
2016-07-02 13:43 - 2016-07-02 13:43 - 00000043 _____ C:\Users\L4k0\Desktop\Nový textový dokument.txt
2016-07-02 13:13 - 2016-07-02 12:19 - 00000000 ____D C:\Windows\Panther
2016-07-02 13:10 - 2016-07-02 13:10 - 00002255 _____ C:\Users\Public\Desktop\Google Chrome.lnk
2016-07-02 13:10 - 2016-07-02 13:10 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome
2016-07-02 13:09 - 2016-07-02 13:52 - 00000928 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2016-07-02 13:09 - 2016-07-02 13:14 - 00000932 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2016-07-02 13:09 - 2016-07-02 13:10 - 00000000 ____D C:\Users\L4k0\AppData\Local\Google
2016-07-02 13:09 - 2016-07-02 13:09 - 00003928 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA
2016-07-02 13:09 - 2016-07-02 13:09 - 00003676 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore
2016-07-02 13:09 - 2016-07-02 13:09 - 00000000 ____D C:\Program Files (x86)\Google
2016-07-02 12:34 - 2016-07-02 12:34 - 00000000 ____D C:\Windows\System32\Tasks\Norton Internet Security
2016-07-02 12:30 - 2016-07-02 12:30 - 00177752 _____ (Symantec Corporation) C:\Windows\system32\Drivers\SYMEVENT64x86.SYS
2016-07-02 12:30 - 2016-07-02 12:30 - 00008222 _____ C:\Windows\system32\Drivers\SYMEVENT64x86.CAT
2016-07-02 12:30 - 2016-07-02 12:30 - 00003236 _____ C:\Windows\System32\Tasks\Norton WSC Integration
2016-07-02 12:30 - 2016-07-02 12:30 - 00002584 _____ C:\Users\Public\Desktop\Norton Internet Security.lnk
2016-07-02 12:30 - 2016-07-02 12:30 - 00000000 ____D C:\Program Files\Common Files\Symantec Shared
2016-07-02 12:29 - 2016-07-02 12:31 - 00000000 ____D C:\ProgramData\Norton
2016-07-02 12:29 - 2016-07-02 12:30 - 00000000 ___RD C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Norton Internet Security
2016-07-02 12:29 - 2016-07-02 12:29 - 00000000 ____D C:\Windows\system32\Drivers\NISx64
2016-07-02 12:29 - 2016-07-02 12:29 - 00000000 ____D C:\ProgramData\NortonInstaller
2016-07-02 12:29 - 2016-07-02 12:29 - 00000000 ____D C:\Program Files (x86)\NortonInstaller
2016-07-02 12:29 - 2016-07-02 12:29 - 00000000 ____D C:\Program Files (x86)\Norton Internet Security
2016-07-02 12:21 - 2016-07-02 12:21 - 00057560 _____ C:\Users\L4k0\AppData\Local\GDIPFONTCACHEV1.DAT
2016-07-02 12:19 - 2016-07-02 12:19 - 00000020 ___SH C:\Users\L4k0\ntuser.ini
2016-07-02 12:19 - 2016-07-02 12:19 - 00000000 ____D C:\Users\L4k0\AppData\Local\VirtualStore
2016-07-02 12:19 - 2016-07-02 12:19 - 00000000 ____D C:\Users\L4k0
2016-07-02 12:19 - 2010-11-21 17:10 - 00000000 ____D C:\Users\L4k0\AppData\Roaming\Media Center Programs
2016-07-02 12:17 - 2016-07-02 12:17 - 00001345 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Media Center.lnk
2016-07-02 12:17 - 2016-07-02 12:17 - 00001326 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows DVD Maker.lnk
2016-07-02 12:15 - 2016-07-02 12:15 - 00000000 ____H C:\Windows\system32\Drivers\Msft_User_WpdFs_01_09_00.Wdf
==================== One Month Modified files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2016-07-02 13:56 - 2009-07-14 07:13 - 00781298 _____ C:\Windows\system32\PerfStringBackup.INI
2016-07-02 13:56 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\inf
2016-07-02 13:51 - 2009-07-14 07:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2016-07-02 13:51 - 2009-07-14 06:45 - 00016640 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2016-07-02 13:51 - 2009-07-14 06:45 - 00016640 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2016-07-02 13:27 - 2009-07-14 05:20 - 00000000 __RHD C:\Users\Public\Libraries
2016-07-02 13:12 - 2009-07-14 07:32 - 00028672 _____ C:\Windows\system32\config\BCD-Template
2016-07-02 13:03 - 2009-07-14 07:32 - 00000000 ___RD C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Games
2016-07-02 13:03 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\PolicyDefinitions
2016-07-02 12:18 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\rescache
2016-07-02 12:17 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\system32\sysprep
2016-07-02 12:14 - 2009-07-14 06:45 - 00274736 _____ C:\Windows\system32\FNTCACHE.DAT
Some files in TEMP:
====================
C:\Users\L4k0\AppData\Local\Temp\MSIAFTERBURNERSETUP.EXE
C:\Users\L4k0\AppData\Local\Temp\SETUP_AFTERBURNER.EXE
C:\Users\L4k0\AppData\Local\Temp\vcredist_x86.exe
==================== Bamital & volsnap =================
(There is no automatic fix for files that do not pass verification.)
C:\Windows\system32\winlogon.exe => File is digitally signed
C:\Windows\system32\wininit.exe => File is digitally signed
C:\Windows\SysWOW64\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\system32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\system32\services.exe => File is digitally signed
C:\Windows\system32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\system32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\system32\rpcss.dll => File is digitally signed
C:\Windows\system32\dnsapi.dll => File is digitally signed
C:\Windows\SysWOW64\dnsapi.dll => File is digitally signed
C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed
LastRegBack: 2016-07-02 12:14
==================== End of FRST.txt ============================
AUDITION
Additional scan result of Farbar Recovery Scan Tool (x64) Version: 02-07-2016
Ran by L4k0 (2016-07-02 14:10:36)
Running from C:\Users\L4k0\Desktop
Windows 7 Home Premium Service Pack 1 (X64) (2016-07-02 10:19:24)
Boot Mode: Normal
==========================================================
==================== Accounts: =============================
Administrator (S-1-5-21-3446584074-721549401-2035689353-500 - Administrator - Disabled)
Guest (S-1-5-21-3446584074-721549401-2035689353-501 - Limited - Disabled)
HomeGroupUser$ (S-1-5-21-3446584074-721549401-2035689353-1002 - Limited - Enabled)
L4k0 (S-1-5-21-3446584074-721549401-2035689353-1000 - Administrator - Enabled) => C:\Users\L4k0
==================== Security Center ========================
(If an entry is included in the fixlist, it will be removed.)
AV: Norton Internet Security (Enabled - Up to date) {63DF5164-9100-186D-2187-8DC619EFD8BF}
AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: Norton Internet Security (Enabled - Up to date) {D8BEB080-B73A-17E3-1B37-B6B462689202}
FW: Norton Internet Security (Enabled) {5BE4D041-DB6F-1935-0AD8-24F3E73C9FC4}
==================== Installed Programs ======================
(Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)
Catalyst Control Center Next Localization BR (Version: 2016.0321.1015.16463 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization CS (Version: 2016.0321.1015.16463 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization DA (Version: 2016.0321.1015.16463 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization DE (Version: 2016.0321.1015.16463 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization EL (Version: 2016.0321.1015.16463 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization ES (Version: 2016.0321.1015.16463 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization FI (Version: 2016.0321.1015.16463 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization FR (Version: 2016.0321.1015.16463 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization HU (Version: 2016.0321.1015.16463 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization CHS (Version: 2016.0321.1015.16463 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization CHT (Version: 2016.0321.1015.16463 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization IT (Version: 2016.0321.1015.16463 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization JA (Version: 2016.0321.1015.16463 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization KO (Version: 2016.0321.1015.16463 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization NL (Version: 2016.0321.1015.16463 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization NO (Version: 2016.0321.1015.16463 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization PL (Version: 2016.0321.1015.16463 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization RU (Version: 2016.0321.1015.16463 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization SV (Version: 2016.0321.1015.16463 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization TH (Version: 2016.0321.1015.16463 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization TR (Version: 2016.0321.1015.16463 - Advanced Micro Devices, Inc.) Hidden
Google Chrome (HKLM-x32\...\Google Chrome) (Version: 26.0.1410.40 - Google Inc.)
Google Update Helper (x32 Version: 1.3.21.115 - Google Inc.) Hidden
Microsoft .NET Framework 4.5 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.50709 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.50727 (HKLM-x32\...\{15134cb0-b767-4960-a911-f2d16ae54797}) (Version: 11.0.50727.1 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.30501 (HKLM-x32\...\{050d4fc8-5d48-4b8f-8972-47c82c46020f}) (Version: 12.0.30501.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501 (HKLM-x32\...\{f65db027-aff3-4070-886a-0d87064aabb1}) (Version: 12.0.30501.0 - Microsoft Corporation)
Norton Internet Security (HKLM-x32\...\NIS) (Version: 21.0.0.100 - Symantec Corporation)
Process Blocker 1.0.13.0 (HKLM\...\{FEC52075-E418-400D-A25C-AE7F366A9C2C}) (Version: 1.0.13.0 - Softros Systems, Inc.)
Vulkan Run Time Libraries 1.0.3.1 (HKLM\...\VulkanRT1.0.3.1) (Version: 1.0.3.1 - LunarG, Inc.)
==================== Custom CLSID (Whitelisted): ==========================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
==================== Scheduled Tasks (Whitelisted) =============
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
Task: {26A850C4-4ADA-4A3C-9145-5B8213738C5C} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2016-07-02] (Google Inc.)
Task: {5485C6C0-51BD-4027-96A7-DA06610F16D3} - System32\Tasks\Norton WSC Integration => C:\Program Files (x86)\Norton Internet Security\Engine\21.0.0.100\WSCStub.exe [2013-08-16] (Symantec Corporation)
Task: {CAD44A45-277A-4837-8D1D-F53384034BE8} - System32\Tasks\Norton Internet Security\Norton Error Processor => C:\Program Files (x86)\Norton Internet Security\Engine\21.0.0.100\SymErr.exe [2013-08-01] (Symantec Corporation)
Task: {D47083C6-EABB-4BF4-8F17-5F9273BA4842} - System32\Tasks\Norton Internet Security\Norton Error Analyzer => C:\Program Files (x86)\Norton Internet Security\Engine\21.0.0.100\SymErr.exe [2013-08-01] (Symantec Corporation)
Task: {DB8507D6-FDD7-4F27-8018-5E24C6C05222} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2016-07-02] (Google Inc.)
(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
==================== Shortcuts =============================
(The entries could be listed to be restored or removed.)
==================== Loaded Modules (Whitelisted) ==============
2015-06-25 17:34 - 2015-06-25 17:34 - 00014336 _____ () C:\Program Files\AMD\CNext\CNext\QtQuick.2\qtquick2plugin.dll
2015-06-25 17:37 - 2015-06-25 17:37 - 00739840 _____ () C:\Program Files\AMD\CNext\CNext\QtQuick\Controls\qtquickcontrolsplugin.dll
2015-06-25 17:35 - 2015-06-25 17:35 - 00014336 _____ () C:\Program Files\AMD\CNext\CNext\QtQuick\Window.2\windowplugin.dll
2015-06-25 17:38 - 2015-06-25 17:38 - 00071168 _____ () C:\Program Files\AMD\CNext\CNext\QtQuick\Layouts\qquicklayoutsplugin.dll
2015-06-25 16:53 - 2015-06-25 16:53 - 00011776 _____ () C:\Program Files\AMD\CNext\CNext\libEGL.dll
2015-06-25 16:51 - 2015-06-25 16:51 - 02013696 _____ () C:\Program Files\AMD\CNext\CNext\libGLESv2.dll
2016-07-02 13:10 - 2013-03-20 08:03 - 00598480 _____ () C:\Program Files (x86)\Google\Chrome\Application\26.0.1410.40\libglesv2.dll
2016-07-02 13:10 - 2013-03-20 08:03 - 00124368 _____ () C:\Program Files (x86)\Google\Chrome\Application\26.0.1410.40\libegl.dll
2016-07-02 13:10 - 2013-03-20 08:04 - 04050896 _____ () C:\Program Files (x86)\Google\Chrome\Application\26.0.1410.40\pdf.dll
2016-07-02 13:10 - 2013-03-20 08:04 - 00390096 _____ () C:\Program Files (x86)\Google\Chrome\Application\26.0.1410.40\ppGoogleNaClPluginChrome.dll
2016-07-02 13:10 - 2013-03-20 08:03 - 01606096 _____ () C:\Program Files (x86)\Google\Chrome\Application\26.0.1410.40\ffmpegsumo.dll
2016-07-02 13:10 - 2013-03-20 08:04 - 12662224 _____ () C:\Program Files (x86)\Google\Chrome\Application\26.0.1410.40\PepperFlash\pepflashplayer.dll
==================== Alternate Data Streams (Whitelisted) =========
(If an entry is included in the fixlist, only the ADS will be removed.)
==================== Safe Mode (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)
==================== Association (Whitelisted) ===============
(If an entry is included in the fixlist, the registry item will be restored to default or removed.)
==================== Internet Explorer trusted/restricted ===============
(If an entry is included in the fixlist, it will be removed from the registry.)
==================== Hosts content: ===============================
(If needed Hosts: directive could be included in the fixlist to reset Hosts.)
2009-07-14 04:34 - 2009-06-10 23:00 - 00000824 ____A C:\Windows\system32\Drivers\etc\hosts
==================== Other Areas ============================
(Currently there is no automatic fix for this section.)
HKU\S-1-5-21-3446584074-721549401-2035689353-1000\Control Panel\Desktop\\Wallpaper -> C:\Users\L4k0\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper.jpg
DNS Servers: 4.2.2.1 - 4.2.2.2
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
Windows Firewall is enabled.
==================== MSCONFIG/TASK MANAGER disabled items ==
(Currently there is no automatic fix for this section.)
==================== FirewallRules (Whitelisted) ===============
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
FirewallRules: [{BC2EF894-D26C-4A10-B57E-6EF57F7A9036}] => (Allow) C:\Program Files\Softros Systems\Process Blocker\Process Blocker.exe
==================== Restore Points =========================
02-07-2016 13:03:10 Inštalátor modulov systému Windows
02-07-2016 13:48:53 Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.50727
02-07-2016 13:49:07 Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.30501
02-07-2016 13:50:40 Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501
02-07-2016 14:00:37 Installed Process Blocker 1.0.13.0
==================== Faulty Device Manager Devices =============
Name:
Description:
Class Guid:
Manufacturer:
Service:
Problem: : This device is disabled. (Code 22)
Resolution: In Device Manager, click "Action", and then click "Enable Device". This starts the Enable Device wizard. Follow the instructions.
==================== Event log errors: =========================
Application errors:
==================
Error: (07/02/2016 01:56:12 PM) (Source: Microsoft-Windows-LoadPerf) (EventID: 3006) (User: NT AUTHORITY)
Description: Unable to read the performance counter strings defined for the 01B language ID. The first DWORD in the Data section contains the Win32 error code.
Error: (07/02/2016 01:56:12 PM) (Source: Microsoft-Windows-LoadPerf) (EventID: 3006) (User: NT AUTHORITY)
Description: Unable to read the performance counter strings defined for the 01B language ID. The first DWORD in the Data section contains the Win32 error code.
Error: (07/02/2016 01:53:32 PM) (Source: Microsoft-Windows-LoadPerf) (EventID: 3006) (User: NT AUTHORITY)
Description: Unable to read the performance counter strings defined for the 01B language ID. The first DWORD in the Data section contains the Win32 error code.
Error: (07/02/2016 01:53:32 PM) (Source: Microsoft-Windows-LoadPerf) (EventID: 3006) (User: NT AUTHORITY)
Description: Unable to read the performance counter strings defined for the 01B language ID. The first DWORD in the Data section contains the Win32 error code.
Error: (07/02/2016 01:53:31 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
Error: (07/02/2016 01:50:34 PM) (Source: MsiInstaller) (EventID: 11904) (User: L4k0-PC)
Description: Product: AMD Drag and Drop Transcoding -- Error 1904.Module C:\Program Files (x86)\Common Files\ATI Technologies\Multimedia\AMDMFTVideoDecoder_32.dll failed to register. HRESULT -2147024770. Contact your support personnel.
Error: (07/02/2016 01:49:22 PM) (Source: MsiInstaller) (EventID: 11723) (User: L4k0-PC)
Description: Product: AMD Install Manager -- Error 1723.There is a problem with this Windows Installer package. A DLL required for this install to complete could not be run. Contact your support personnel or package vendor. Action SetInstallDir, entry: SetInstallDir, library: C:\Windows\Installer\MSI3110.tmp
Error: (07/02/2016 01:47:17 PM) (Source: Microsoft-Windows-LoadPerf) (EventID: 3006) (User: L4k0-PC)
Description: Unable to read the performance counter strings defined for the 01B language ID. The first DWORD in the Data section contains the Win32 error code.
Error: (07/02/2016 01:47:17 PM) (Source: Microsoft-Windows-LoadPerf) (EventID: 3006) (User: L4k0-PC)
Description: Unable to read the performance counter strings defined for the 01B language ID. The first DWORD in the Data section contains the Win32 error code.
Error: (07/02/2016 01:47:16 PM) (Source: Microsoft-Windows-LoadPerf) (EventID: 3006) (User: L4k0-PC)
Description: Unable to read the performance counter strings defined for the 01B language ID. The first DWORD in the Data section contains the Win32 error code.
System errors:
=============
==================== Memory info ===========================
Processor: AMD Phenom(tm) II X4 945 Processor
Percentage of memory in use: 27%
Total physical RAM: 8191.11 MB
Available physical RAM: 5940.08 MB
Total Virtual: 16380.43 MB
Available Virtual: 13758.37 MB
==================== Drives ================================
Drive c: () (Fixed) (Total:117.19 GB) (Free:91.91 GB) NTFS
Drive d: () (Fixed) (Total:348.47 GB) (Free:348.37 GB) NTFS
==================== MBR & Partition Table ==================
========================================================
Disk: 0 (MBR Code: Windows 7 or 8) (Size: 465.8 GB) (Disk ID: 4D154D14)
Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=117.2 GB) - (Type=07 NTFS)
Partition 3: (Not Active) - (Size=348.5 GB) - (Type=07 NTFS)
==================== End of Addition.txt ============================