Zde
------------------------
Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version:31-12-2015
Ran by ERIK (administrator) on DOMA225 (18-08-2016 22:45:49)
Running from C:\Users\ERIK\Desktop\Windows apps
Loaded Profiles: ERIK (Available Profiles: ERIK & Guest)
Platform: Windows 8 Enterprise (X64) Language: English (United States)
Internet Explorer Version 10 (Default browser: Chrome)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool:
http://www.geekstogo.com/forum/topic/33 ... scan-tool/
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
() C:\Program Files (x86)\AVG Web TuneUp\WtuSystemSupport.exe
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(Optimal Software s.r.o.) C:\Program Files (x86)\Zrychleni Pocitace\PCSUService.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe
(Adobe Systems Incorporated) C:\Program Files (x86)\Common Files\Adobe\Adobe Desktop Common\ElevationManager\AdobeUpdateService.exe
(Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(LogMeIn, Inc.) C:\Program Files (x86)\LogMeIn Hamachi\LMIGuardianSvc.exe
(Google Inc.) C:\Program Files (x86)\Google\Update\1.3.31.5\GoogleCrashHandler.exe
(Google Inc.) C:\Program Files (x86)\Google\Update\1.3.31.5\GoogleCrashHandler64.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
(Skype Technologies S.A.) C:\Program Files (x86)\Skype\Phone\Skype.exe
() C:\Windows\SysWOW64\PnkBstrA.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Apple Inc.) C:\Program Files (x86)\iTunes\iTunesHelper.exe
() C:\Program Files (x86)\Gaming Keyboard\Monitor.EXE
(Microsoft Corporation) C:\Program Files (x86)\Microsoft Office\Office14\ONENOTEM.EXE
(Wondershare) C:\Program Files (x86)\Common Files\Wondershare\Wondershare Helper Compact\WSHelper.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
() C:\Program Files (x86)\Gaming Keyboard\OSD.exe
(TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\Version9\TeamViewer_Service.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(TuneUp Software) C:\Program Files (x86)\TuneUp Utilities 2014\TuneUpUtilitiesService64.exe
(TuneUp Software) C:\Program Files (x86)\TuneUp Utilities 2014\TuneUpUtilitiesApp64.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
(Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe
(Power Software Ltd) C:\Program Files\PowerISO\PWRISOVM.EXE
(Hewlett-Packard) C:\Program Files (x86)\HP\HP Software Update\hpwuschd2.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastUI.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(Adobe Systems, Incorporated) C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGSService.exe
(HP Inc.) C:\Program Files (x86)\Hewlett-Packard\HP Support Solutions\HPSupportSolutionsFrameworkService.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jucheck.exe
(InstallShield Software) C:\Users\ERIK\AppData\Roaming\AVAST Software\ISSCH\issch.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Microsoft Corporation) C:\Windows\System32\Taskmgr.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
==================== Registry (Whitelisted) ===========================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe [7199448 2013-10-01] (Realtek Semiconductor)
HKLM\...\Run: [V0700Pin.dll] => RunDLL32.exe V0700Pin.dll,RunDLL32EP 514,/d:2
HKLM\...\Run: [NvBackend] => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe [2403104 2014-07-25] (NVIDIA Corporation)
HKLM\...\Run: [ShadowPlay] => C:\Windows\system32\rundll32.exe C:\Windows\system32\nvspcap64.dll,ShadowPlayOnSystemStart
HKLM\...\Run: [AdobeAAMUpdater-1.0] => C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [508128 2016-03-22] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [V0700Mon.exe] => C:\Windows\V0700Mon.exe
HKLM-x32\...\Run: [Adobe Creative Cloud] => C:\Program Files (x86)\Adobe\Adobe Creative Cloud\ACC\Creative Cloud.exe [2313408 2016-04-07] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [seznam-listicka-distribuce] => C:\Program Files (x86)\Seznam.cz\distribution\szninstall.exe [1062472 2013-05-16] ()
HKLM-x32\...\Run: [iTunesHelper] => C:\Program Files (x86)\iTunes\iTunesHelper.exe [157480 2014-10-15] (Apple Inc.)
HKLM-x32\...\Run: [Gaming Keyboard] => C:\Program Files (x86)\Gaming Keyboard\Monitor.exe [479232 2014-01-16] ()
HKLM-x32\...\Run: [Wondershare Helper Compact.exe] => C:\Program Files (x86)\Common Files\Wondershare\Wondershare Helper Compact\WSHelper.exe [2087264 2014-09-11] (Wondershare)
HKLM-x32\...\Run: [PWRISOVM.EXE] => C:\Program Files\PowerISO\PWRISOVM.EXE [408888 2015-06-08] (Power Software Ltd)
HKLM-x32\...\Run: [LogMeIn Hamachi Ui] => C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe [5565448 2015-11-12] (LogMeIn Inc.)
HKLM-x32\...\Run: [HP Software Update] => C:\Program Files (x86)\Hp\HP Software Update\HPWuSchd2.exe [96056 2013-05-30] (Hewlett-Packard)
HKLM-x32\...\Run: [] => [X]
HKLM-x32\...\Run: [AvastUI.exe] => C:\Program Files\AVAST Software\Avast\AvastUI.exe [9071752 2016-07-31] (AVAST Software)
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [595504 2016-01-29] (Oracle Corporation)
HKU\S-1-5-21-2796967165-1696306274-2783790974-1001\...\Run: [DAEMON Tools Lite] => D:\hry\DAEMON Tools Lite\DTLite.exe [3696912 2014-03-04] (Disc Soft Ltd)
HKU\S-1-5-21-2796967165-1696306274-2783790974-1001\...\Run: [EADM] => C:\Program Files (x86)\Origin\Origin.exe [3639280 2016-02-05] (Electronic Arts)
HKU\S-1-5-21-2796967165-1696306274-2783790974-1001\...\Run: [cz.seznam.software.autoupdate] => C:\Users\ERIK\AppData\Roaming\Seznam.cz\szninstall.exe [1062472 2013-05-16] ()
HKU\S-1-5-21-2796967165-1696306274-2783790974-1001\...\Run: [cz.seznam.software.szndesktop] => C:\Users\ERIK\AppData\Roaming\Seznam.cz\bin\wszndesktop.exe [92664 2013-04-12] ()
HKU\S-1-5-21-2796967165-1696306274-2783790974-1001\...\Run: [GoogleChromeAutoLaunch_5998AE56BE14438E63B1EE3391313A39] => C:\Program Files (x86)\Google\Chrome\Application\chrome.exe [961352 2016-08-03] (Google Inc.)
HKU\S-1-5-21-2796967165-1696306274-2783790974-1001\...\Run: [Steam] => D:\Steam\steam.exe [2852128 2016-08-03] (Valve Corporation)
HKU\S-1-5-21-2796967165-1696306274-2783790974-1001\...\Run: [Skype] => C:\Program Files (x86)\Skype\Phone\Skype.exe [29494400 2016-07-13] (Skype Technologies S.A.)
HKU\S-1-5-21-2796967165-1696306274-2783790974-1001\...\Policies\Explorer: [NoDriveTypeAutoRun] 0x95000000
AppInit_DLLs: C:\ProgramData\Quoteex\AlphaAnfan.dll => C:\ProgramData\Quoteex\AlphaAnfan.dll [358912 2016-08-11] ()
AppInit_DLLs-x32: C:\ProgramData\Quoteex\Sumzap.dll => C:\ProgramData\Quoteex\Sumzap.dll [248320 2016-08-11] ()
ShellIconOverlayIdentifiers: [ AccExtIco1] -> {AB9CF9F8-8A96-4F9D-BF21-CE85714C3A47} => C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CoreSyncExtension\CoreSync_x64.dll [2016-04-01] ()
ShellIconOverlayIdentifiers: [ AccExtIco2] -> {853B7E05-C47D-4985-909A-D0DC5C6D7303} => C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CoreSyncExtension\CoreSync_x64.dll [2016-04-01] ()
ShellIconOverlayIdentifiers: [ AccExtIco3] -> {42D38F2E-98E9-4382-B546-E24E4D6D04BB} => C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CoreSyncExtension\CoreSync_x64.dll [2016-04-01] ()
ShellIconOverlayIdentifiers: [###MegaShellExtPending] -> {056D528D-CE28-4194-9BA3-BA2E9197FF8C} => C:\Users\ERIK\AppData\Local\MEGAsync\ShellExtX64.dll [2014-05-01] ()
ShellIconOverlayIdentifiers: [###MegaShellExtSynced] -> {05B38830-F4E9-4329-978B-1DD28605D202} => C:\Users\ERIK\AppData\Local\MEGAsync\ShellExtX64.dll [2014-05-01] ()
ShellIconOverlayIdentifiers: [###MegaShellExtSyncing] -> {0596C850-7BDD-4C9D-AFDF-873BE6890637} => C:\Users\ERIK\AppData\Local\MEGAsync\ShellExtX64.dll [2014-05-01] ()
ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShA64.dll [2016-07-29] (AVAST Software)
ShellIconOverlayIdentifiers: [DropboxExt1] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\ERIK\AppData\Roaming\Dropbox\bin\DropboxExt64.22.dll [2013-09-11] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [DropboxExt2] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\ERIK\AppData\Roaming\Dropbox\bin\DropboxExt64.22.dll [2013-09-11] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [DropboxExt3] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\ERIK\AppData\Roaming\Dropbox\bin\DropboxExt64.22.dll [2013-09-11] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [DropboxExt4] -> {FB314EDC-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\ERIK\AppData\Roaming\Dropbox\bin\DropboxExt64.22.dll [2013-09-11] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [###MegaShellExtPending] -> {056D528D-CE28-4194-9BA3-BA2E9197FF8C} => C:\Users\ERIK\AppData\Local\MEGAsync\ShellExtX32.dll [2014-05-01] ()
ShellIconOverlayIdentifiers-x32: [###MegaShellExtSynced] -> {05B38830-F4E9-4329-978B-1DD28605D202} => C:\Users\ERIK\AppData\Local\MEGAsync\ShellExtX32.dll [2014-05-01] ()
ShellIconOverlayIdentifiers-x32: [###MegaShellExtSyncing] -> {0596C850-7BDD-4C9D-AFDF-873BE6890637} => C:\Users\ERIK\AppData\Local\MEGAsync\ShellExtX32.dll [2014-05-01] ()
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\McAfee Security Scan Plus.lnk [2015-11-06]
ShortcutTarget: McAfee Security Scan Plus.lnk -> C:\Program Files (x86)\McAfee Security Scan\3.11.163\SSScheduler.exe (No File)
Startup: C:\Users\ERIK\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Monitor Ink Alerts - HP Deskjet 3520 series.lnk [2016-02-08]
Startup: C:\Users\ERIK\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Výřezy obrazovky a spuštění aplikace OneNote 2010.lnk [2016-02-18]
ShortcutTarget: Výřezy obrazovky a spuštění aplikace OneNote 2010.lnk -> C:\Program Files (x86)\Microsoft Office\Office14\ONENOTEM.EXE (Microsoft Corporation)
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
ProxyServer: [S-1-5-21-2796967165-1696306274-2783790974-1001] => http=127.0.0.1:14326;https=127.0.0.1:14326
Hosts: There are more than one entry in Hosts. See Hosts section of Addition.txt
Tcpip\..\Interfaces\{A45B3B47-1DEE-488D-8E7A-98105E31809C}: [DhcpNameServer] 7.254.254.254
Tcpip\..\Interfaces\{D7BF9759-483B-4DF8-9D39-8EE151365322}: [NameServer] 8.8.8.8,8.8.4.4
Tcpip\..\Interfaces\{D7BF9759-483B-4DF8-9D39-8EE151365322}: [DhcpNameServer] 217.30.64.53 217.30.64.54
Internet Explorer:
==================
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = about:blank
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://
www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://
www.microsoft.com/isapi/redir.dll?prd=ie&ar=msnhome
HKU\S-1-5-21-2796967165-1696306274-2783790974-1001\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://%66%65%65%64.%73%6F%6E%69%63-%73%65%61%72%63%68.%63%6F%6D/?p=mKO_AwFzXIpYRaHdGKBRGNclVS1AC6sNoHoTG1nEZQLY5Wto32I9TJr4zSevMZGVSYe5tA4WQb8Bn-ibjZmwwXTFEZ7t-UqS8zgcIicvjuI75ixbPhtqDAhm3R_HgiE0evHuLP5ypB8NAtNRicCQlepZAMMxC6OThffuo5DJ_RgOi9xxaUw9e4UOzeMTWS5JA5PGfrC6ng,,&q={searchTerms}
HKU\S-1-5-21-2796967165-1696306274-2783790974-1001\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://%66%65%65%64.%68%65%6C%70%65%72%62%61%72.%63%6F%6D/?p=mKO_AwFzXIpYRaHdGKBRGNclVS1AC6sNoHoTG1nEZQLY5Wto32I9TJr4zSevMZGVSYe5tA4WQb8Bn-ibjZmwwXTFEZ7t-UqS8zgcIicvjuI75ixXbZtQ9savvXf_EaaI7rbCxP-Jz3i7InAK5uKg9dgRhKwwAPaXe7Z_k81Li848CFCj79ka4dnSwHaO19X1rQnWWW9Blw,,
HKU\S-1-5-21-2796967165-1696306274-2783790974-1001\Software\Microsoft\Internet Explorer\Main,Search Bar = hxxp://%66%65%65%64.%73%6F%6E%69%63-%73%65%61%72%63%68.%63%6F%6D/?p=mKO_AwFzXIpYRaHdGKBRGNclVS1AC6sNoHoTG1nEZQLY5Wto32I9TJr4zSevMZGVSYe5tA4WQb8Bn-ibjZmwwXTFEZ7t-UqS8zgcIicvjuI75ixbPhtqDAhm3R_HgiE0evHuLP5ypB8NAtNRicCQlepZAMMxC6OThffuo5DJ_RgOi9xxaUw9e4UOzeMTWS5JA5PGfrC6ng,,&q={searchTerms}
HKU\S-1-5-21-2796967165-1696306274-2783790974-1001\Software\Microsoft\Internet Explorer\Main,SearchAssistant = hxxp://%66%65%65%64.%73%6F%6E%69%63-%73%65%61%72%63%68.%63%6F%6D/?p=mKO_AwFzXIpYRaHdGKBRGNclVS1AC6sNoHoTG1nEZQLY5Wto32I9TJr4zSevMZGVSYe5tA4WQb8Bn-ibjZmwwXTFEZ7t-UqS8zgcIicvjuI75ixbPhtqDAhm3R_HgiE0evHuLP5ypB8NAtNRicCQlepZAMMxC6OThffuo5DJ_RgOi9xxaUw9e4UOzeMTWS5JA5PGfrC6ng,,&q={searchTerms}
SearchScopes: HKLM-x32 -> DefaultScope {ielnksrch} URL =
SearchScopes: HKLM-x32 -> ielnksrch URL = hxxp://%66%65%65%64.%73%6F%6E%69%63-%73%65%61%72%63%68.%63%6F%6D/?p=mKO_AwFzXIpYRaHdGKBRGNclVS1AC6sNoHoTG1nEZQLY5Wto32I9TJr4zSevMZGVSYe5tA4WQb8Bn-ibjZmwwXTFEZ7t-UqS8zgcIicvjuI75ixbPhtqDAhm3R_HgiE0evHuLP5ypB8NAtNRicCQlepZAMMxC6OThffuo5DJ_RgOi9xxaUw9e4UOzeMTWS5JA5PGfrC6ng,,&q={searchTerms}
SearchScopes: HKU\S-1-5-21-2796967165-1696306274-2783790974-1001 -> DefaultScope {ielnksrch} URL = hxxp://%66%65%65%64.%73%6F%6E%69%63-%73%65%61%72%63%68.%63%6F%6D/?p=mKO_AwFzXIpYRaHdGKBRGNclVS1AC6sNoHoTG1nEZQLY5Wto32I9TJr4zSevMZGVSYe5tA4WQb8Bn-ibjZmwwXTFEZ7t-UqS8zgcIicvjuI75ixbPhtqDAhm3R_HgiE0evHuLP5ypB8NAtNRicCQlepZAMMxC6OThffuo5DJ_RgOi9xxaUw9e4UOzeMTWS5JA5PGfrC6ng,,&q={searchTerms}
SearchScopes: HKU\S-1-5-21-2796967165-1696306274-2783790974-1001 -> 16944E13E82DEFA97D39592013C2B7A8 URL = hxxp://
www.firmy.cz/phr/{searchTerms}
SearchScopes: HKU\S-1-5-21-2796967165-1696306274-2783790974-1001 -> 33D267CDA73706E77445E11F79A59BC4 URL = hxxp://
www.mapy.cz/?sourceid=quicksearch_6826& ... earchTerms}
SearchScopes: HKU\S-1-5-21-2796967165-1696306274-2783790974-1001 -> D409C7645CA7CA4C24B1AFA73B1AEF36 URL = hxxp://videa.seznam.cz/?q={searchTerms}
SearchScopes: HKU\S-1-5-21-2796967165-1696306274-2783790974-1001 -> DF91290F8D6EC8584060B5957DE2FB6C URL = hxxp://
www.zbozi.cz/?sourceid=quicksearch_6826&q={searchTerms}
SearchScopes: HKU\S-1-5-21-2796967165-1696306274-2783790974-1001 -> {632F07F3-19A1-4d16-A23F-E6CE9486BAB5} URL = hxxp://search.seznam.cz/?sourceid=quicksearch_6826&q={searchTerms}
SearchScopes: HKU\S-1-5-21-2796967165-1696306274-2783790974-1001 -> {ielnksrch} URL = hxxp://%66%65%65%64.%73%6F%6E%69%63-%73%65%61%72%63%68.%63%6F%6D/?p=mKO_AwFzXIpYRaHdGKBRGNclVS1AC6sNoHoTG1nEZQLY5Wto32I9TJr4zSevMZGVSYe5tA4WQb8Bn-ibjZmwwXTFEZ7t-UqS8zgcIicvjuI75ixbPhtqDAhm3R_HgiE0evHuLP5ypB8NAtNRicCQlepZAMMxC6OThffuo5DJ_RgOi9xxaUw9e4UOzeMTWS5JA5PGfrC6ng,,&q={searchTerms}
BHO: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll [2016-07-01] (AVAST Software)
BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL [2013-03-06] (Microsoft Corporation)
BHO: Визуальные закладки -> {D5FEC983-01DB-414A-9456-AF95AC9ED7B5} -> No File
BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_74\bin\ssv.dll [2016-03-29] (Oracle Corporation)
BHO-x32: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll [2016-07-01] (AVAST Software)
BHO-x32: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL [2013-03-06] (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_74\bin\jp2ssv.dll [2016-03-29] (Oracle Corporation)
Toolbar: HKU\S-1-5-21-2796967165-1696306274-2783790974-1001 -> No Name - {91397D20-1446-11D4-8AF4-0040CA1127B6} - No File
FireFox:
========
FF ProfilePath: C:\Users\ERIK\AppData\Roaming\Mozilla\Firefox\Profiles\nahd6ha2.default
FF Homepage: C:\ProgramData\Quoteexs\ff.HP
FF NewTab: C:\ProgramData\Quoteexs\ff.NT
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_22_0_0_209.dll [2016-07-12] ()
FF Plugin: @esn/npbattlelog,version=2.6.2 -> C:\Program Files (x86)\Battlelog Web Plugins\2.6.2\npbattlelogx64.dll [No File]
FF Plugin: @esn/npbattlelog,version=2.7.0 -> C:\Program Files (x86)\Battlelog Web Plugins\2.7.0\npbattlelogx64.dll [No File]
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files\Microsoft Silverlight\5.1.50428.0\npctrl.dll [2016-04-27] ( Microsoft Corporation)
FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~1\MICROS~1\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation)
FF Plugin: adobe.com/AdobeAAMDetect -> C:\Program Files (x86)\Adobe\Adobe Creative Cloud\Utils\npAdobeAAMDetect64.dll [2016-04-07] (Adobe Systems)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_22_0_0_209.dll [2016-07-12] ()
FF Plugin-x32: @Apple.com/iTunes,version=1.0 -> C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll [2014-02-18] ()
FF Plugin-x32: @esn/npbattlelog,version=2.6.2 -> C:\Program Files (x86)\Battlelog Web Plugins\2.6.2\npbattlelog.dll [No File]
FF Plugin-x32: @esn/npbattlelog,version=2.7.0 -> C:\Program Files (x86)\Battlelog Web Plugins\2.7.0\npbattlelog.dll [No File]
FF Plugin-x32: @Google.com/GoogleEarthPlugin -> C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll [2015-05-21] (Google)
FF Plugin-x32: @java.com/DTPlugin,version=11.74.2 -> C:\Program Files (x86)\Java\jre1.8.0_74\bin\dtplugin\npDeployJava1.dll [2016-03-29] (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=11.74.2 -> C:\Program Files (x86)\Java\jre1.8.0_74\bin\plugin2\npjp2.dll [2016-03-29] (Oracle Corporation)
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files (x86)\Microsoft Silverlight\5.1.50428.0\npctrl.dll [2016-04-27] ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL [2010-03-24] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=16.4.3528.0331 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2014-03-31] (Microsoft Corporation)
FF Plugin-x32: @nvidia.com/3DVision -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll [2014-07-02] (NVIDIA Corporation)
FF Plugin-x32: @nvidia.com/3DVisionStreaming -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll [2014-07-02] (NVIDIA Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.31.5\npGoogleUpdate3.dll [2016-07-29] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.31.5\npGoogleUpdate3.dll [2016-07-29] (Google Inc.)
FF Plugin-x32: @videolan.org/vlc,version=2.1.2 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2016-01-21] (VideoLAN)
FF Plugin-x32: @videolan.org/vlc,version=2.2.2 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2016-01-21] (VideoLAN)
FF Plugin-x32: @virtools.com/3DviaPlayer -> C:\Program Files (x86)\Virtools\3D Life Player\npvirtools.dll [2012-04-05] (Dassault Systèmes)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll [2015-12-18] (Adobe Systems Inc.)
FF Plugin-x32: adobe.com/AdobeAAMDetect -> C:\Program Files (x86)\Adobe\Adobe Creative Cloud\Utils\npAdobeAAMDetect32.dll [2016-04-07] (Adobe Systems)
FF Plugin HKU\S-1-5-21-2796967165-1696306274-2783790974-1001: @Skype Limited.com/Facebook Video Calling Plugin -> C:\Users\ERIK\AppData\Local\Facebook\Video\Skype\npFacebookVideoCalling.dll [2014-07-24] (Skype Limited)
FF Plugin HKU\S-1-5-21-2796967165-1696306274-2783790974-1001: @unity3d.com/UnityPlayer,version=1.0 -> C:\Users\ERIK\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll [2015-10-20] (Unity Technologies ApS)
FF SearchPlugin: C:\Users\ERIK\AppData\Roaming\Mozilla\Firefox\Profiles\nahd6ha2.default\searchplugins\findit.xml [2016-08-11]
FF SearchPlugin: C:\Users\ERIK\AppData\Roaming\Mozilla\Firefox\Profiles\nahd6ha2.default\searchplugins\firmy.cz-080222.xml [2015-10-27]
FF SearchPlugin: C:\Users\ERIK\AppData\Roaming\Mozilla\Firefox\Profiles\nahd6ha2.default\searchplugins\mapy.cz-080222.xml [2015-10-27]
FF SearchPlugin: C:\Users\ERIK\AppData\Roaming\Mozilla\Firefox\Profiles\nahd6ha2.default\searchplugins\seznam.cz-080222.xml [2015-10-27]
FF SearchPlugin: C:\Users\ERIK\AppData\Roaming\Mozilla\Firefox\Profiles\nahd6ha2.default\searchplugins\videa.seznam.cz-080222.xml [2015-10-27]
FF SearchPlugin: C:\Users\ERIK\AppData\Roaming\Mozilla\Firefox\Profiles\nahd6ha2.default\searchplugins\zbozi.cz-080222.xml [2015-10-27]
FF Extension: Tab Auto Reload - C:\Users\ERIK\AppData\Roaming\Mozilla\Firefox\Profiles\nahd6ha2.default\extensions\
TabAutoReload@schuzak.jp.xpi [2016-01-23]
FF HKLM\...\Firefox\Extensions: [
wrc@avast.com] - C:\Program Files\AVAST Software\Avast\WebRep\FF
FF Extension: Avast Online Security - C:\Program Files\AVAST Software\Avast\WebRep\FF [2016-07-29]
FF HKLM\...\Firefox\Extensions: [
sp@avast.com] - C:\Program Files\AVAST Software\Avast\SafePrice\FF
FF Extension: Avast SafePrice - C:\Program Files\AVAST Software\Avast\SafePrice\FF [2016-07-29]
FF HKLM-x32\...\Firefox\Extensions: [
wrc@avast.com] - C:\Program Files\AVAST Software\Avast\WebRep\FF
FF HKLM-x32\...\Firefox\Extensions: [
sp@avast.com] - C:\Program Files\AVAST Software\Avast\SafePrice\FF
Chrome:
=======
CHR HomePage: Default -> search.ask.com/?gct=hp
CHR StartupUrls: Default -> "","
www.google.com"
CHR DefaultSearchURL: Default -> hxxp://%66%65%65%64.%73%6F%6E%69%63-%73%65%61%72%63%68.%63%6F%6D/?p=mKO_AwFzXIpYRaHdGKBRGNclVS1AC6sNoHoTG1nEZQLY5Wto32I9TJr4zSevMZGVSYe5tA4WQb8Bn-ibjZmwwXTFEZ7t-UqS8zgcIicvjuI75ixbKQWnCeyLwVeCEyex84qwwtwSMM0ZOORI5LL-KmgSzbxZMwt1esl_buZ3Z92rGCJaS2vPbaY75_nxD_oYrc2u0PsePQ,,&q={searchTerms}
CHR DefaultSearchKeyword: Default -> feed.sonic-search.com
CHR DefaultSuggestURL: Default -> hxxps://search.yahoo.com/sugg/chrome?output=fxjson&appid=crmas&command={searchTerms}
CHR Profile: C:\Users\ERIK\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (Easy Auto Refresh) - C:\Users\ERIK\AppData\Local\Google\Chrome\User Data\Default\Extensions\aabcgdmkeabbnleenpncegpcngjpnjkc [2016-07-12]
CHR Extension: (Prezentace Google) - C:\Users\ERIK\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2016-08-11]
CHR Extension: (Dokumenty Google) - C:\Users\ERIK\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2016-08-11]
CHR Extension: (Disk Google) - C:\Users\ERIK\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2016-08-11]
CHR Extension: (Seznam Lištička - Email) - C:\Users\ERIK\AppData\Local\Google\Chrome\User Data\Default\Extensions\bgjpfhpjcgdppjbgnpnjllokbmcdllig [2015-02-18]
CHR Extension: (Seznam Lištička - Slovník) - C:\Users\ERIK\AppData\Local\Google\Chrome\User Data\Default\Extensions\blmojkbhnkkphngknkmgccmlenfaelkd [2016-02-09]
CHR Extension: (YouTube) - C:\Users\ERIK\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2016-08-11]
CHR Extension: (Avast Online Security) - C:\Users\ERIK\AppData\Local\Google\Chrome\User Data\Default\Extensions\daanglpcpkjjlkhcbladppjphglbigam [2016-08-10]
CHR Extension: (Avast Passwords) - C:\Users\ERIK\AppData\Local\Google\Chrome\User Data\Default\Extensions\emhginjpijfggbofeediiojmdlmlkoik [2016-08-18]
CHR Extension: (Avast SafePrice) - C:\Users\ERIK\AppData\Local\Google\Chrome\User Data\Default\Extensions\eofcbnmajmjmplflapaojjnihcjkigck [2016-08-18]
CHR Extension: (Wize) - C:\Users\ERIK\AppData\Local\Google\Chrome\User Data\Default\Extensions\feeilhmlfcpfchpbgoknoeefdkbgionj [2016-08-14]
CHR Extension: (Tabulky Google) - C:\Users\ERIK\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2016-08-11]
CHR Extension: (KB SSL Enforcer) - C:\Users\ERIK\AppData\Local\Google\Chrome\User Data\Default\Extensions\flcpelgcagfhfoegekianiofphddckof [2015-01-24]
CHR Extension: (Dokumenty Google offline) - C:\Users\ERIK\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2016-08-11]
CHR Extension: (AdBlock) - C:\Users\ERIK\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom [2016-07-29]
CHR Extension: (Invite All Friends on Facebook) - C:\Users\ERIK\AppData\Local\Google\Chrome\User Data\Default\Extensions\inmmhkeajgflmokoaaoadgkhhmibjbpj [2016-08-14]
CHR Extension: (Skype) - C:\Users\ERIK\AppData\Local\Google\Chrome\User Data\Default\Extensions\lifbcibllhkdhoafpjfnlhfpfgnpldfl [2016-05-23]
CHR Extension: (Platby Internetového obchodu Chrome) - C:\Users\ERIK\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2016-04-02]
CHR Extension: (Seznam Lištička - Rychlá volba) - C:\Users\ERIK\AppData\Local\Google\Chrome\User Data\Default\Extensions\olfeabkoenfaoljndfecamgilllcpiak [2015-10-28]
CHR Extension: (Визуальные закладки) - C:\Users\ERIK\AppData\Local\Google\Chrome\User Data\Default\Extensions\pchfckkccldkbclgdepkaonamkignanh [2016-08-01]
CHR Extension: (Gmail) - C:\Users\ERIK\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2016-08-11]
CHR Extension: (Chrome Media Router) - C:\Users\ERIK\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2016-08-18]
CHR HKLM-x32\...\Chrome\Extension: [bopakagnckmlgajfccecajhnimjiiedh] - hxxp://clients2.google.com/service/update2/crx
CHR HKLM-x32\...\Chrome\Extension: [daanglpcpkjjlkhcbladppjphglbigam] - hxxps://clients2.google.com/service/update2/crx
CHR HKLM-x32\...\Chrome\Extension: [emhginjpijfggbofeediiojmdlmlkoik] - C:\Program Files\AVAST Software\Avast\pam\Chrome\pam.crx <not found>
CHR HKLM-x32\...\Chrome\Extension: [eofcbnmajmjmplflapaojjnihcjkigck] - hxxps://clients2.google.com/service/update2/crx
CHR HKLM-x32\...\Chrome\Extension: [gomekmidlodglbbmalcneegieacbdmki] - C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChrome.crx <not found>
CHR HKLM-x32\...\Chrome\Extension: [lifbcibllhkdhoafpjfnlhfpfgnpldfl] - C:\Program Files (x86)\Skype\Toolbars\ChromeExtension\skype_chrome_extension.crx <not found>
CHR HKLM-x32\...\Chrome\Extension: [pchfckkccldkbclgdepkaonamkignanh] - hxxp://clients2.google.com/service/update2/crx
==================== Services (Whitelisted) ========================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R2 AdobeUpdateService; C:\Program Files (x86)\Common Files\Adobe\Adobe Desktop Common\ElevationManager\AdobeUpdateService.exe [694464 2016-04-07] (Adobe Systems Incorporated)
R2 AGSService; C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGSService.exe [2159832 2016-08-12] (Adobe Systems, Incorporated)
R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [197640 2016-07-29] (AVAST Software)
S4 backlh; C:\ProgramData\Logic Handler\set.exe [2089472 2016-08-11] () [File not signed]
S3 BEService; C:\Program Files (x86)\Common Files\BattlEye\BEService.exe [1392648 2016-07-31] ()
S3 EasyAntiCheat; C:\Windows\SysWOW64\EasyAntiCheat.exe [236840 2015-04-13] (EasyAntiCheat Ltd)
R2 HPSupportSolutionsFrameworkService; C:\Program Files (x86)\Hewlett-Packard\HP Support Solutions\HPSupportSolutionsFrameworkService.exe [29760 2016-07-04] (HP Inc.)
R2 LMIGuardianSvc; C:\Program Files (x86)\LogMeIn Hamachi\LMIGuardianSvc.exe [417552 2015-11-12] (LogMeIn, Inc.)
S2 MBAMScheduler; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe [1809720 2014-05-12] (Malwarebytes Corporation)
S2 MBAMService; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe [860472 2014-05-12] (Malwarebytes Corporation)
R2 NvNetworkService; C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe [1720608 2014-07-25] (NVIDIA Corporation)
R2 NvStreamSvc; C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe [18956064 2014-07-25] (NVIDIA Corporation)
S3 Origin Client Service; C:\Program Files (x86)\Origin\OriginClientService.exe [2104840 2016-02-05] (Electronic Arts)
S3 OverwolfUpdater; C:\Program Files (x86)\Overwolf\OverwolfUpdater.exe [1310448 2016-08-14] (Overwolf LTD)
R2 PCSUService; C:\Program Files (x86)\Zrychleni Pocitace\PCSUService.exe [445600 2016-01-28] (Optimal Software s.r.o.)
R2 PnkBstrA; C:\Windows\system32\PnkBstrA.exe [76152 2015-03-23] ()
R2 PnkBstrA; C:\Windows\SysWOW64\PnkBstrA.exe [76152 2016-05-21] ()
S2 SCService; C:\Program Files (x86)\Zrychleni Pocitace\SpeedCheckerService.exe [67232 2016-01-28] (Optimal Software s.r.o.)
S3 Survarium Update Service; D:\hry\Survarium\game\binaries\x86\survarium_service.exe [97880 2016-06-09] ()
S3 Survarium-Steam Update Service; D:\hry\SteamLibrary\steamapps\common\Survarium\game\binaries\x86\survarium_service.exe [76408 2015-04-14] ()
R2 TuneUp.UtilitiesSvc; C:\Program Files (x86)\TuneUp Utilities 2014\TuneUpUtilitiesService64.exe [2145080 2014-07-16] (TuneUp Software)
S3 TunngleService; C:\Program Files (x86)\Tunngle\TnglCtrl.exe [872432 2016-06-23] (Tunngle.net GmbH)
S3 VSStandardCollectorService140; C:\Program Files (x86)\Microsoft Visual Studio 14.0\Team Tools\DiagnosticsHub\Collector\StandardCollector.Service.exe [52968 2015-07-07] (Microsoft Corporation)
S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [16056 2015-07-06] (Microsoft Corporation)
R2 WtuSystemSupport; C:\Program Files (x86)\AVG Web TuneUp\WtuSystemSupport.exe [1164688 2015-12-26] ()
===================== Drivers (Whitelisted) ==========================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R2 aswHwid; C:\Windows\system32\drivers\aswHwid.sys [37656 2016-07-29] (AVAST Software)
R1 aswKbd; C:\Windows\system32\drivers\aswKbd.sys [37144 2016-07-29] (AVAST Software)
R2 aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [108816 2016-07-29] (AVAST Software)
R1 aswRdr; C:\Windows\system32\drivers\aswRdr2.sys [103064 2016-07-29] (AVAST Software)
R0 aswRvrt; C:\Windows\System32\Drivers\aswRvrt.sys [74544 2016-07-29] (AVAST Software)
R1 aswSnx; C:\Windows\system32\drivers\aswSnx.sys [968536 2016-07-29] (AVAST Software)
R1 aswSP; C:\Windows\system32\drivers\aswSP.sys [513496 2016-07-29] (AVAST Software)
R2 aswStm; C:\Windows\system32\drivers\aswStm.sys [163416 2016-07-29] (AVAST Software)
R0 aswVmm; C:\Windows\System32\Drivers\aswVmm.sys [292704 2016-08-05] (AVAST Software)
R3 AU8168; C:\Windows\system32\DRIVERS\au630x64.sys [792648 2013-09-23] (Realtek )
R1 dtsoftbus01; C:\Windows\System32\drivers\dtsoftbus01.sys [283064 2014-05-29] (Disc Soft Ltd)
S0 ebdrv; C:\Windows\System32\drivers\evbda.sys [3265256 2012-09-20] (Broadcom Corporation)
R3 Hamachi; C:\Windows\system32\DRIVERS\Hamdrv.sys [45680 2015-11-12] (LogMeIn Inc.)
R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25816 2014-05-12] (Malwarebytes Corporation)
S3 MBAMSwissArmy; C:\Windows\system32\drivers\MBAMSwissArmy.sys [122584 2014-09-28] (Malwarebytes Corporation)
S3 MBAMWebAccessControl; C:\Windows\system32\drivers\mwac.sys [64216 2014-05-12] (Malwarebytes Corporation)
R3 NvStreamKms; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys [20256 2014-07-25] (NVIDIA Corporation)
R3 nvvad_WaveExtensible; C:\Windows\system32\drivers\nvvad64v.sys [40392 2014-03-31] (NVIDIA Corporation)
S0 prohlp01; C:\Windows\SysWOW64\drivers\prohlp01.sys [75936 2002-10-05] (Protection Technology Co.) [File not signed]
S0 prohlp02; C:\Windows\SysWOW64\drivers\prohlp02.sys [94464 2003-04-28] (StarForce Technologies, Inc.) [File not signed]
S0 prosync1; C:\Windows\SysWOW64\drivers\prosync1.sys [6848 2003-04-04] (StarForce Technologies, Inc.) [File not signed]
R3 SensorsSimulatorDriver; C:\Windows\system32\DRIVERS\WUDFRd.sys [198656 2012-07-26] (Microsoft Corporation)
S0 sfhlp01; C:\Windows\SysWOW64\drivers\sfhlp01.sys [4448 2003-04-29] (StarForce Technologies, Inc.) [File not signed]
S3 ssudserd; C:\Windows\system32\DRIVERS\ssudserd.sys [206080 2014-01-22] (DEVGURU Co., LTD.(
www.devguru.co.kr))
R3 tap0901t; C:\Windows\system32\DRIVERS\tap0901t.sys [39464 2016-04-27] (Tunngle.net GmbH)
R3 TuneUpUtilitiesDrv; C:\Program Files (x86)\TuneUp Utilities 2014\TuneUpUtilitiesDriver64.sys [14112 2013-08-21] (TuneUp Software)
S3 V0700Vid; C:\Windows\system32\DRIVERS\V0700Vid.sys [393920 2011-09-06] (Creative Technology Ltd.)
S3 WdBoot; C:\Windows\system32\drivers\WdBoot.sys [44560 2015-07-06] (Microsoft Corporation)
S3 WdFilter; C:\Windows\system32\drivers\WdFilter.sys [281944 2015-07-06] (Microsoft Corporation)
S2 BstHdDrv; \??\C:\Program Files (x86)\BlueStacks\HD-Hypervisor-amd64.sys [X]
S3 catchme; \??\C:\ComboFix\catchme.sys [X]
S3 cpuz138; \??\C:\Users\ERIK\AppData\Local\Temp\cpuz138\cpuz138_x64.sys [X]
S1 prodrv05; \SystemRoot\System32\drivers\prodrv05.sys [X]
S1 prodrv06; \SystemRoot\System32\drivers\prodrv06.sys [X]
S3 xhunter1; \??\C:\Windows\xhunter1.sys [X]
S1 {f9d2f209-1697-4837-85f2-d88e4c9f7c81}Gw64; system32\drivers\{f9d2f209-1697-4837-85f2-d88e4c9f7c81}Gw64.sys [X]
==================== NetSvcs (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
==================== One Month Created files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2016-08-18 22:45 - 2016-08-18 22:45 - 00000000 ____D C:\FRST
2016-08-14 22:23 - 2016-08-14 22:54 - 00000000 ____D C:\Users\ERIK\Desktop\zidan photos
2016-08-11 15:43 - 2016-08-11 15:55 - 293374631 _____ C:\Users\ERIK\Downloads\max-life-pack-version-1.5.7z
2016-08-11 15:36 - 2016-08-11 15:38 - 58379465 _____ C:\Users\ERIK\Downloads\Civilian-Units-v065alpha.7z
2016-08-11 15:30 - 2016-08-11 15:38 - 206915894 _____ C:\Users\ERIK\Downloads\NIArms-AK-Rifle-Pack-version-2.0.rar
2016-08-11 15:30 - 2016-08-11 15:30 - 08251092 _____ C:\Users\ERIK\Downloads\NIArms-Core-version-1.0.rar
2016-08-11 15:29 - 2016-08-11 15:36 - 184312262 _____ C:\Users\ERIK\Downloads\1st-chechen-war-period-russian-federation-armed-forces-version-1.02.rar
2016-08-11 15:25 - 2016-08-11 15:27 - 44408949 _____ C:\Users\ERIK\Downloads\delta-force-altis-v0-8-2.7z
2016-08-11 15:24 - 2016-08-11 15:24 - 11395414 _____ C:\Users\ERIK\Downloads\AAS_Arma3_Pack_V8.rar
2016-08-11 15:20 - 2016-08-11 15:21 - 26830117 _____ C:\Users\ERIK\Downloads\Max-Cops-and-Robbers-Modv35.7z
2016-08-11 11:49 - 2016-08-11 12:35 - 00000000 ____D C:\Program Files (x86)\ContentPush
2016-08-11 11:49 - 2016-08-11 11:49 - 00000000 ____D C:\Program Files (x86)\WeatherChickn
2016-08-11 11:48 - 2016-08-18 22:26 - 00000000 ____D C:\Program Files (x86)\Zrychleni Pocitace
2016-08-11 11:48 - 2016-08-18 21:14 - 00000382 _____ C:\Windows\Tasks\PC SpeedUp Service Deactivator.job
2016-08-11 11:48 - 2016-08-12 23:44 - 00000000 ____D C:\ProgramData\CloudPrinter
2016-08-11 11:48 - 2016-08-12 13:21 - 00000000 ____D C:\ProgramData\Quoteex
2016-08-11 11:48 - 2016-08-11 11:48 - 07118336 _____ C:\Users\ERIK\AppData\Roaming\agent.dat
2016-08-11 11:48 - 2016-08-11 11:48 - 01900478 _____ C:\Users\ERIK\AppData\Roaming\Rontop.tst
2016-08-11 11:48 - 2016-08-11 11:48 - 00848437 _____ C:\Users\ERIK\AppData\Roaming\Stronglab.bin
2016-08-11 11:48 - 2016-08-11 11:48 - 00138240 _____ C:\Users\ERIK\AppData\Roaming\Installer.dat
2016-08-11 11:48 - 2016-08-11 11:48 - 00126464 _____ C:\Users\ERIK\AppData\Roaming\noah.dat
2016-08-11 11:48 - 2016-08-11 11:48 - 00126464 _____ C:\Users\ERIK\AppData\Roaming\lobby.dat
2016-08-11 11:48 - 2016-08-11 11:48 - 00072710 _____ C:\Users\ERIK\AppData\Roaming\Statdex.tst
2016-08-11 11:48 - 2016-08-11 11:48 - 00070704 _____ C:\Users\ERIK\AppData\Roaming\Config.xml
2016-08-11 11:48 - 2016-08-11 11:48 - 00054272 _____ C:\Users\ERIK\AppData\Roaming\ApplicationHosting.dat
2016-08-11 11:48 - 2016-08-11 11:48 - 00018432 _____ C:\Users\ERIK\AppData\Roaming\Main.dat
2016-08-11 11:48 - 2016-08-11 11:48 - 00018384 _____ C:\Users\ERIK\AppData\Roaming\InstallationConfiguration.xml
2016-08-11 11:48 - 2016-08-11 11:48 - 00005568 _____ C:\Users\ERIK\AppData\Roaming\md.xml
2016-08-11 11:48 - 2016-08-11 11:48 - 00002744 _____ C:\Windows\System32\Tasks\PC SpeedUp Service Deactivator
2016-08-11 11:48 - 2016-08-11 11:48 - 00002397 _____ C:\Windows\SysWOW64\findit.xml
2016-08-11 11:48 - 2016-08-11 11:48 - 00000000 ____D C:\ProgramData\Quoteexs
2016-08-11 11:48 - 2016-08-11 11:48 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Zrychleni Pocitace
2016-08-11 11:48 - 2016-08-11 11:48 - 00000000 ____D C:\ProgramData\Logic Handler
2016-08-11 11:47 - 2016-08-11 11:47 - 00495182 _____ C:\Users\ERIK\Downloads\nomansskykeygen.gz
2016-08-10 18:17 - 2016-08-10 18:17 - 00003888 _____ C:\Windows\System32\Tasks\SafeZone scheduled Autoupdate 1458977659
2016-08-10 18:07 - 2016-08-10 18:07 - 00000000 ____D C:\Windows\pss
2016-08-10 17:35 - 2016-08-10 17:36 - 160675640 _____ C:\Users\ERIK\Downloads\Homefront.The.Revolution.Hybrid.Crack-Voksi.rar
2016-08-10 16:29 - 2016-08-10 16:29 - 00003318 _____ C:\Windows\System32\Tasks\InstallShield Update Service
2016-08-10 11:06 - 2016-08-10 11:06 - 00000805 _____ C:\Users\ERIK\Desktop\Homefront The Revolution.lnk
2016-08-10 11:06 - 2016-08-10 11:06 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Homefront The Revolution
2016-08-10 09:50 - 2016-08-10 09:50 - 00000000 ____D C:\Users\ERIK\AppData\Local\Microsoft Windows
2016-08-10 00:04 - 2016-08-10 00:04 - 00000709 _____ C:\Users\Public\Desktop\Takedown Red Sabre.lnk
2016-08-10 00:04 - 2016-08-10 00:04 - 00000709 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Takedown Red Sabre.lnk
2016-08-05 20:33 - 2016-08-05 20:34 - 18790484 _____ C:\Users\ERIK\Downloads\pilgrimage-v1-94.7z
2016-08-05 20:33 - 2016-08-05 20:34 - 17255758 _____ C:\Users\ERIK\Downloads\sp_altis-resistance_v1-23.altis.7z
2016-08-05 20:31 - 2016-08-05 20:32 - 05023320 _____ C:\Users\ERIK\Downloads\sp-cox_duws_v0-8b.altis.7z
2016-08-04 21:34 - 2016-08-04 21:37 - 1280982268 _____ C:\Users\ERIK\Downloads\Zootropolis---animovany,akcni,dobrodruzny---2016---cz-dab..avi
2016-08-04 18:29 - 2016-08-04 19:12 - 1061301760 _____ C:\Users\ERIK\Downloads\NATO-SF-Russian-Spetsnaz-Vehicles-version-1.4.7z
2016-08-04 18:29 - 2016-08-04 19:03 - 847273201 _____ C:\Users\ERIK\Downloads\NATO-SF-Russian-Spetsnaz-Weapons-version-1.2 (1).7z
2016-08-04 17:03 - 2016-08-04 17:09 - 129381146 _____ C:\Users\ERIK\Downloads\taliban-fighters-version-rc-16 (1).7z
2016-08-04 17:02 - 2016-08-04 17:19 - 403841135 _____ C:\Users\ERIK\Downloads\USSOCOM-75th-Ranger-Navy-SEALs-DEVGRU-Delta-Force-version-1.8 (1).7z
2016-08-04 00:13 - 2016-08-04 00:48 - 870188084 _____ C:\Users\ERIK\Downloads\Leights-OPFOR-Pack-version-1.9.7z.crdownload
2016-08-04 00:11 - 2016-08-04 00:48 - 911242692 _____ C:\Users\ERIK\Downloads\NATO-SF-Russian-Spetsnaz-Vehicles-version-1.4.7z.crdownload
2016-08-04 00:11 - 2016-08-04 00:27 - 403841135 _____ C:\Users\ERIK\Downloads\USSOCOM-75th-Ranger-Navy-SEALs-DEVGRU-Delta-Force-version-1.8.7z
2016-08-04 00:05 - 2016-08-04 00:11 - 129381146 _____ C:\Users\ERIK\Downloads\taliban-fighters-version-rc-16.7z
2016-08-01 00:19 - 2016-08-01 00:19 - 00000000 ____H C:\Windows\system32\Drivers\Msft_User_LocationProvider_01_11_00.Wdf
2016-08-01 00:02 - 2016-08-01 00:20 - 00000000 ____D C:\Users\ERIK\Desktop\adelakutz fotky
2016-07-29 12:15 - 2016-07-29 12:15 - 00391496 _____ (AVAST Software) C:\Windows\system32\aswBoot.exe
2016-07-29 12:14 - 2016-07-29 12:14 - 00053208 _____ (AVAST Software) C:\Windows\avastSS.scr
==================== One Month Modified files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2016-08-18 22:45 - 2016-03-26 16:11 - 00000000 ___RD C:\Users\ERIK\Desktop\Windows apps
2016-08-18 22:45 - 2012-07-26 07:37 - 00000000 ____D C:\Windows
2016-08-18 22:34 - 2015-11-07 15:58 - 00000830 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job
2016-08-18 22:31 - 2013-12-11 19:40 - 00000000 ____D C:\Users\ERIK\AppData\Roaming\Skype
2016-08-18 22:29 - 2012-07-26 10:12 - 00000000 ____D C:\Windows\tracing
2016-08-18 22:27 - 2015-07-07 17:28 - 00000000 ____D C:\Users\ERIK\AppData\Local\LogMeIn Hamachi
2016-08-18 22:26 - 2016-02-02 18:09 - 00000976 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2016-08-18 22:20 - 2016-02-02 18:09 - 00000972 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2016-08-18 22:19 - 2015-05-04 17:50 - 00065536 _____ C:\Windows\system32\Ikeext.etl
2016-08-18 22:18 - 2013-12-10 23:20 - 00000000 ____D C:\ProgramData\NVIDIA
2016-08-18 22:18 - 2012-07-26 09:22 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2016-08-18 21:31 - 2016-06-22 21:31 - 00000002 _____ C:\END
2016-08-18 21:31 - 2016-05-29 21:30 - 00000000 ____D C:\Program Files (x86)\Overwolf
2016-08-18 21:02 - 2014-08-08 19:05 - 00000000 ____D C:\Users\ERIK\AppData\Local\Adobe
2016-08-14 22:54 - 2014-04-14 21:03 - 06210048 ___SH C:\Users\ERIK\Downloads\Thumbs.db
2016-08-14 12:40 - 2015-06-19 17:17 - 00000000 ____D C:\Users\ERIK\AppData\Roaming\Tunngle
2016-08-14 10:42 - 2016-07-16 18:43 - 00000000 ____D C:\ProgramData\Tunngle
2016-08-14 10:40 - 2015-06-15 22:17 - 00000000 ____D C:\Users\ERIK\AppData\Local\Arma 3
2016-08-13 07:44 - 2015-11-14 12:55 - 00000892 _____ C:\Windows\Tasks\Adobe Flash Player PPAPI Notifier.job
2016-08-12 13:18 - 2016-02-05 14:25 - 00000344 _____ C:\Windows\Tasks\HPCeeScheduleForERIK.job
2016-08-12 00:10 - 2016-03-26 16:17 - 00000000 ____D C:\Users\ERIK\Documents\Visual Studio 2015
2016-08-11 18:40 - 2016-02-05 14:25 - 00003156 _____ C:\Windows\System32\Tasks\HPCeeScheduleForERIK
2016-08-11 18:40 - 2013-12-10 22:57 - 00000000 ____D C:\Users\ERIK
2016-08-11 11:51 - 2012-07-26 07:37 - 00000000 ____D C:\Windows\Inf
2016-08-11 11:49 - 2016-01-24 08:17 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox
2016-08-11 11:48 - 2016-01-06 19:50 - 00001169 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk
2016-08-11 11:48 - 2016-01-06 19:50 - 00001163 _____ C:\Users\Public\Desktop\Mozilla Firefox.lnk
2016-08-11 11:48 - 2014-08-18 18:23 - 00002193 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Opera.lnk
2016-08-11 11:48 - 2013-12-11 19:59 - 00002201 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2016-08-11 11:48 - 2013-12-10 22:58 - 00001422 _____ C:\Users\ERIK\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
2016-08-10 18:17 - 2016-03-26 09:34 - 00001003 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avast SafeZone Browser.lnk
2016-08-10 18:14 - 2012-07-26 07:26 - 00262144 ___SH C:\Windows\system32\config\BBI
2016-08-10 18:08 - 2015-06-19 17:18 - 00000000 _____ C:\Windows\SysWOW64\Access.dat
2016-08-10 16:29 - 2016-03-26 09:29 - 00000000 ____D C:\Users\ERIK\AppData\Roaming\AVAST Software
2016-08-10 16:27 - 2013-12-12 19:51 - 00000000 ____D C:\Windows\SysWOW64\directx
2016-08-10 11:26 - 2013-12-11 09:20 - 00000000 ____D C:\ProgramData\Microsoft Help
2016-08-10 11:25 - 2013-12-10 23:34 - 00000000 ____D C:\Windows\system32\MRT
2016-08-10 11:13 - 2013-12-10 23:34 - 147640136 ____C (Microsoft Corporation) C:\Windows\system32\MRT.exe
2016-08-10 11:06 - 2016-03-26 15:58 - 00094720 ___SH C:\Users\ERIK\Desktop\Thumbs.db
2016-08-10 09:57 - 2014-05-31 16:39 - 00000000 ____D C:\Users\ERIK\AppData\Roaming\uTorrent
2016-08-05 00:16 - 2016-03-26 09:28 - 00292704 _____ (AVAST Software) C:\Windows\system32\Drivers\aswvmm.sys
2016-08-01 00:19 - 2015-05-25 18:14 - 00000000 ____D C:\Users\ERIK\AppData\Local\Windows Live
2016-07-31 12:19 - 2012-07-26 10:12 - 00000000 ____D C:\Windows\AUInstallAgent
2016-07-31 12:17 - 2012-07-26 10:12 - 00000000 ___HD C:\Program Files\WindowsApps
2016-07-29 12:21 - 2016-02-02 18:09 - 00003948 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA
2016-07-29 12:21 - 2016-02-02 18:09 - 00003712 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore
2016-07-29 12:16 - 2016-03-26 09:28 - 00003922 _____ C:\Windows\System32\Tasks\avast! Emergency Update
2016-07-29 12:15 - 2016-03-26 09:28 - 00513496 _____ (AVAST Software) C:\Windows\system32\Drivers\aswSP.sys
2016-07-29 12:15 - 2016-03-26 09:28 - 00163416 _____ (AVAST Software) C:\Windows\system32\Drivers\aswStm.sys
2016-07-29 12:15 - 2016-03-26 09:28 - 00108816 _____ (AVAST Software) C:\Windows\system32\Drivers\aswMonFlt.sys
2016-07-29 12:15 - 2016-03-26 09:28 - 00103064 _____ (AVAST Software) C:\Windows\system32\Drivers\aswRdr2.sys
2016-07-29 12:15 - 2016-03-26 09:28 - 00074544 _____ (AVAST Software) C:\Windows\system32\Drivers\aswRvrt.sys
2016-07-29 12:15 - 2016-03-26 09:28 - 00037656 _____ (AVAST Software) C:\Windows\system32\Drivers\aswHwid.sys
2016-07-29 12:14 - 2016-03-26 09:33 - 00037144 _____ (AVAST Software) C:\Windows\system32\Drivers\aswKbd.sys
2016-07-29 12:14 - 2016-03-26 09:28 - 00968536 _____ (AVAST Software) C:\Windows\system32\Drivers\aswSnx.sys
2016-07-28 20:50 - 2014-11-26 18:59 - 00000000 ___RD C:\Program Files (x86)\Skype
2016-07-28 20:50 - 2013-12-11 09:29 - 00000000 ____D C:\ProgramData\Skype
2016-07-27 21:25 - 2013-12-11 00:11 - 00504488 ____N (Microsoft Corporation) C:\Windows\system32\MpSigStub.exe
2016-07-19 12:21 - 2012-07-26 10:12 - 00000000 ____D C:\Windows\system32\FxsTmp
==================== Files in the root of some directories =======
2016-08-11 11:48 - 2016-08-11 11:48 - 7118336 _____ () C:\Users\ERIK\AppData\Roaming\agent.dat
2016-08-11 11:48 - 2016-08-11 11:48 - 0054272 _____ () C:\Users\ERIK\AppData\Roaming\ApplicationHosting.dat
2014-05-31 14:17 - 2014-05-31 14:17 - 0000000 _____ () C:\Users\ERIK\AppData\Roaming\bitlord_log.txt
2016-08-11 11:48 - 2016-08-11 11:48 - 0070704 _____ () C:\Users\ERIK\AppData\Roaming\Config.xml
2016-08-11 11:48 - 2016-08-11 11:48 - 0018384 _____ () C:\Users\ERIK\AppData\Roaming\InstallationConfiguration.xml
2016-08-11 11:48 - 2016-08-11 11:48 - 0138240 _____ () C:\Users\ERIK\AppData\Roaming\Installer.dat
2016-08-11 11:48 - 2016-08-11 11:48 - 0126464 _____ () C:\Users\ERIK\AppData\Roaming\lobby.dat
2016-08-11 11:48 - 2016-08-11 11:48 - 0018432 _____ () C:\Users\ERIK\AppData\Roaming\Main.dat
2016-08-11 11:48 - 2016-08-11 11:48 - 0005568 _____ () C:\Users\ERIK\AppData\Roaming\md.xml
2016-08-11 11:48 - 2016-08-11 11:48 - 0126464 _____ () C:\Users\ERIK\AppData\Roaming\noah.dat
2016-08-11 11:48 - 2016-08-11 11:48 - 1900478 _____ () C:\Users\ERIK\AppData\Roaming\Rontop.tst
2016-08-11 11:48 - 2016-08-11 11:48 - 0072710 _____ () C:\Users\ERIK\AppData\Roaming\Statdex.tst
2016-08-11 11:48 - 2016-08-11 11:48 - 0848437 _____ () C:\Users\ERIK\AppData\Roaming\Stronglab.bin
2016-08-11 11:48 - 2016-08-11 11:48 - 0032038 _____ () C:\Users\ERIK\AppData\Roaming\uninstall_temp.ico
2016-05-25 13:56 - 2016-05-25 13:56 - 0000000 ____H () C:\Users\ERIK\AppData\Local\BITFD6B.tmp
2016-03-25 11:35 - 2016-03-25 11:35 - 0000000 ___SH () C:\Users\ERIK\AppData\Local\LumaEmu
2016-03-20 21:40 - 2016-03-20 21:40 - 0000000 _____ () C:\Users\ERIK\AppData\Local\{1550C119-D136-45F2-8418-54FA4F1E02E9}
2016-05-25 13:56 - 2016-05-25 13:56 - 0000000 _____ () C:\Users\ERIK\AppData\Local\{B91CA2F2-E955-40FD-B763-83F547739B88}
2015-09-30 18:14 - 2015-09-30 18:14 - 0000000 _____ () C:\Users\ERIK\AppData\Local\{EDA499EE-C7CD-4DE3-AC2E-463886C17FD1}
2016-02-05 14:09 - 2016-02-05 14:09 - 0000057 _____ () C:\ProgramData\Ament.ini
Some files in TEMP:
====================
C:\Users\ERIK\AppData\Local\Temp\333.exe
C:\Users\ERIK\AppData\Local\Temp\360net.dll
C:\Users\ERIK\AppData\Local\Temp\360NetBase.dll
C:\Users\ERIK\AppData\Local\Temp\360NetBase64.dll
C:\Users\ERIK\AppData\Local\Temp\360NetUL.dll
C:\Users\ERIK\AppData\Local\Temp\BCA1.tmpcrt.dll
C:\Users\ERIK\AppData\Local\Temp\BCF0.tmpcrt.dll
C:\Users\ERIK\AppData\Local\Temp\setup.exe
C:\Users\ERIK\AppData\Local\Temp\utils.dll
==================== Bamital & volsnap =================
(There is no automatic fix for files that do not pass verification.)
C:\Windows\system32\winlogon.exe => File is digitally signed
C:\Windows\system32\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\system32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\system32\services.exe => File is digitally signed
C:\Windows\system32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\system32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\system32\rpcss.dll => File is digitally signed
C:\Windows\system32\dnsapi.dll => File is digitally signed
C:\Windows\SysWOW64\dnsapi.dll => File is digitally signed
C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed
LastRegBack: 2016-08-14 11:04
==================== End of FRST.txt ============================