Závada a Kontrola logu
Napsal: 22 lis 2016 14:17
Ahoj mam problem ohledne notasu , po zapnuti nebo restartu notasu mam black screen ale dostanu se pomoci crtl+alt+del do správce zařízeni a ukončím podivuhodny proces který blokuje completne cely notas a vubec netusim jak ho mam najit , na to ho jeste smazat ... v přiloze je FRST log + screen obrazovky kde jsou přesne procesi ktere bezi po restartu notasu a nedovoli notas dál pracovat nebo nabehnout na plochu s ikonama ...byl by někdo schopný a pomohl by mi s moji situací ???
Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 20-11-2016 01
Ran by NaspeR (administrator) on NASPER-PC (22-11-2016 16:34:53)
Running from C:\Users\NaspeR\Desktop
Loaded Profiles: NaspeR (Available Profiles: NaspeR)
Platform: Windows 7 Ultimate Service Pack 1 (X64) Language: Angličtina (Spojené státy)
Internet Explorer Version 8 (Default browser: Chrome)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/33 ... scan-tool/
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
(Microsoft Corporation) C:\Windows\System32\wlanext.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe
(Atheros Commnucations) C:\Program Files (x86)\Bluetooth Suite\AdminService.exe
(Node.js) C:\Program Files (x86)\NVIDIA Corporation\NvNode\NVIDIA Web Helper.exe
(Dritek System Inc.) C:\Program Files (x86)\Launch Manager\dsiwmis.exe
(Intel(R) Corporation) C:\Program Files\Intel\iCLS Client\HeciServer.exe
(Dritek System Inc.) C:\Program Files (x86)\Launch Manager\LMworker.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\Jhi_service.exe
(LogMeIn, Inc.) C:\Program Files (x86)\LogMeIn Hamachi\x64\LMIGuardianSvc.exe
(Dritek System Inc.) C:\Program Files (x86)\Launch Manager\LMutilps32.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\GeForce Experience Service\nvwirelesscontroller.exe
(Atheros) C:\Program Files (x86)\Atheros\Ath_WlanAgent.exe
(LogMeIn Inc.) C:\Program Files (x86)\LogMeIn Hamachi\x64\hamachi-2.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NvContainer\nvcontainer.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(Intel Corporation) C:\Windows\System32\igfxpers.exe
(ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDCtrl.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
(ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDCtrlHelper.exe
(Dritek System Inc.) C:\Program Files (x86)\Launch Manager\LManager.exe
(Piriform Ltd) C:\Program Files\CCleaner\CCleaner64.exe
(Dolby Laboratories Inc.) C:\Dolby PCEE4\pcee4.exe
(Dritek System Inc.) C:\Program Files (x86)\Launch Manager\MMDx64Fx.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\avastui.exe
(Intel Corporation) C:\Windows\System32\igfxext.exe
(Intel Corporation) C:\Windows\System32\igfxsrvc.exe
(Skillbrains) C:\Program Files (x86)\Skillbrains\lightshot\5.4.0.1\Lightshot.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Skype Technologies S.A.) C:\Program Files (x86)\Skype\Phone\Skype.exe
(PandoraTV) C:\KMPlayer\KMPlayer.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(forum.viry.cz) C:\Users\NaspeR\Desktop\FRSTLauncher.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
==================== Registry (Whitelisted) ====================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [ETDCtrl] => C:\Program Files\Elantech\ETDCtrl.exe [2821936 2012-03-07] (ELAN Microelectronics Corp.)
HKLM\...\Run: [RtHDVCpl] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [12343400 2011-12-27] (Realtek Semiconductor)
HKLM\...\Run: [RtHDVBg_Dolby] => C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [1156712 2011-11-15] (Realtek Semiconductor)
HKLM\...\Run: [IntelTBRunOnce] => wscript.exe //b //nologo "C:\Program Files\Intel\TurboBoost\RunTBGadgetOnce.vbs"
HKLM\...\Run: [ShadowPlay] => "C:\Windows\system32\rundll32.exe" C:\Windows\system32\nvspcap64.dll,ShadowPlayOnSystemStart
HKLM-x32\...\Run: [IAStorIcon] => C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [284440 2012-02-01] (Intel Corporation)
HKLM-x32\...\Run: [LManager] => C:\Program Files (x86)\Launch Manager\LManager.exe [1105488 2012-03-23] (Dritek System Inc.)
HKLM-x32\...\Run: [Dolby Home Theater v4] => C:\Dolby PCEE4\pcee4.exe [506712 2011-06-01] (Dolby Laboratories Inc.)
HKLM-x32\...\Run: [AvastUI.exe] => C:\Program Files\AVAST Software\Avast\AvastUI.exe [9080768 2016-11-15] (AVAST Software)
HKLM-x32\...\Run: [GrooveMonitor] => C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe [31016 2006-10-26] (Microsoft Corporation)
HKLM-x32\...\Run: [Lightshot] => C:\Program Files (x86)\Skillbrains\lightshot\Lightshot.exe [225944 2016-07-11] ()
HKLM-x32\...\Run: [LogMeIn Hamachi Ui] => C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe [5565960 2016-11-11] (LogMeIn Inc.)
Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation)
HKU\S-1-5-21-2205024274-236154989-1138663683-1000\...\Run: [DAEMON Tools Lite] => C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe [3673728 2012-11-06] (DT Soft Ltd)
HKU\S-1-5-21-2205024274-236154989-1138663683-1000\...\Run: [CCleaner Monitoring] => C:\Program Files\CCleaner\CCleaner64.exe [8641240 2016-02-12] (Piriform Ltd)
HKU\S-1-5-21-2205024274-236154989-1138663683-1000\...\Run: [UFX Start] => C:\ProgramData\JSCPXA\UFX.exe
HKU\S-1-5-21-2205024274-236154989-1138663683-1000\...\MountPoints2: {2dbd70c9-3b93-11e6-9c5b-806e6f6e6963} - E:\AutoRun\AutoRunX\AutoRunX.exe
HKU\S-1-5-21-2205024274-236154989-1138663683-1000\...\MountPoints2: {a9000636-3b8f-11e6-afc0-806e6f6e6963} - E:\AutoRun\AutoRunX\AutoRunX.exe
HKU\S-1-5-18\...\RunOnce: [SPReview] => C:\Windows\System32\SPReview\SPReview.exe [301568 2016-10-31] (Microsoft Corporation)
AppInit_DLLs: C:\Windows\system32\nvinitx.dll => C:\Windows\system32\nvinitx.dll [177952 2016-07-11] (NVIDIA Corporation)
AppInit_DLLs-x32: C:\Windows\SysWOW64\nvinit.dll => C:\Windows\SysWOW64\nvinit.dll [155768 2016-07-11] (NVIDIA Corporation)
ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShA64.dll [2016-09-09] (AVAST Software)
GroupPolicy: Restriction <======= ATTENTION
GroupPolicy\User: Restriction <======= ATTENTION
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
Tcpip\Parameters: [DhcpNameServer] 10.10.10.1
Tcpip\..\Interfaces\{248A6460-987F-42C5-AAF7-C0AD5C75696C}: [DhcpNameServer] 7.254.254.254
Tcpip\..\Interfaces\{2F34CD87-E306-46CA-8C62-A2A533E840FB}: [DhcpNameServer] 10.10.10.1
Tcpip\..\Interfaces\{E04FD461-BE03-45D2-8C7A-886F0F91A499}: [DhcpNameServer] 10.10.10.1
ManualProxies:
Internet Explorer:
==================
HKU\S-1-5-21-2205024274-236154989-1138663683-1000\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
SearchScopes: HKU\S-1-5-21-2205024274-236154989-1138663683-1000 -> DefaultScope {FFEBBF0A-C22C-4172-89FF-45215A135AC7} URL = hxxp://go.mail.ru/distib/ep/?q={SearchTerms}&product_id=%7BC7F9878F-D1CC-4142-881C-47164E52D35D%7D&gp=811014
SearchScopes: HKU\S-1-5-21-2205024274-236154989-1138663683-1000 -> {FFEBBF0A-C22C-4172-89FF-45215A135AC7} URL = hxxp://go.mail.ru/distib/ep/?q={SearchTerms}&product_id=%7BC7F9878F-D1CC-4142-881C-47164E52D35D%7D&gp=811014
BHO: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll [2016-10-24] (AVAST Software)
BHO-x32: CIESpeechBHO Class -> {8D10F6C4-0E01-4BD4-8601-11AC1FDF8126} -> C:\Program Files (x86)\Bluetooth Suite\IEPlugIn.dll [2012-02-20] (Atheros Commnucations)
BHO-x32: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll [2016-10-24] (AVAST Software)
Filter: deflate - {8f6b0360-b80d-11d0-a9b3-006097942311} - C:\Windows\system32\urlmon.dll [2010-11-20] (Microsoft Corporation)
Filter-x32: deflate - {8f6b0360-b80d-11d0-a9b3-006097942311} - C:\Windows\SysWOW64\urlmon.dll [2010-11-20] (Microsoft Corporation)
Filter: gzip - {8f6b0360-b80d-11d0-a9b3-006097942311} - C:\Windows\system32\urlmon.dll [2010-11-20] (Microsoft Corporation)
Filter-x32: gzip - {8f6b0360-b80d-11d0-a9b3-006097942311} - C:\Windows\SysWOW64\urlmon.dll [2010-11-20] (Microsoft Corporation)
FireFox:
========
FF HKLM\...\Firefox\Extensions: [wrc@avast.com] - C:\Program Files\AVAST Software\Avast\WebRep\FF
FF Extension: (Avast Online Security) - C:\Program Files\AVAST Software\Avast\WebRep\FF [2016-09-09]
FF HKLM\...\Firefox\Extensions: [sp@avast.com] - C:\Program Files\AVAST Software\Avast\SafePrice\FF
FF Extension: (Avast SafePrice) - C:\Program Files\AVAST Software\Avast\SafePrice\FF [2016-09-09]
FF HKLM-x32\...\Firefox\Extensions: [wrc@avast.com] - C:\Program Files\AVAST Software\Avast\WebRep\FF
FF HKLM-x32\...\Firefox\Extensions: [sp@avast.com] - C:\Program Files\AVAST Software\Avast\SafePrice\FF
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=2.0.59 -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll [2012-01-06] (Intel Corporation)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll [2012-01-06] (Intel Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.31.5\npGoogleUpdate3.dll [2016-10-07] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.31.5\npGoogleUpdate3.dll [2016-10-07] (Google Inc.)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll [2016-06-30] (Adobe Systems Inc.)
Chrome:
=======
CHR DefaultProfile: Default
CHR HomePage: Default -> mail.ru/cnt/11956636?rciguc__PARAM__
CHR StartupUrls: Default -> "hxxps://www.google.cz/"
CHR DefaultSearchURL: Default -> hxxps://inline.go.mail.ru/search?inline_comp=dse&q={searchTerms}&fr=chxtn12.0.11
CHR DefaultSearchKeyword: Default -> mail.ru
CHR DefaultSuggestURL: Default -> hxxp://suggests.go.mail.ru/chrome?q={searchTerms}
CHR Profile: C:\Users\NaspeR\AppData\Local\Google\Chrome\User Data\Default [2016-11-22]
CHR Extension: (Prezentace Google) - C:\Users\NaspeR\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2016-10-07]
CHR Extension: (Dokumenty Google) - C:\Users\NaspeR\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2016-10-07]
CHR Extension: (Disk Google) - C:\Users\NaspeR\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2016-10-07]
CHR Extension: (App Launcher for Messenger) - C:\Users\NaspeR\AppData\Local\Google\Chrome\User Data\Default\Extensions\bllmngcdibgbgjnginpehneeofhbmdjm [2016-10-28]
CHR Extension: (YouTube) - C:\Users\NaspeR\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2016-10-07]
CHR Extension: (Adblock Plus) - C:\Users\NaspeR\AppData\Local\Google\Chrome\User Data\Default\Extensions\cfhdojbkjhnklbpkdaibdccddilifddb [2016-10-26]
CHR Extension: (Tabulky Google) - C:\Users\NaspeR\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2016-10-07]
CHR Extension: (Dokumenty Google offline) - C:\Users\NaspeR\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2016-10-07]
CHR Extension: (Platby Internetového obchodu Chrome) - C:\Users\NaspeR\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2016-10-07]
CHR Extension: (Gmail) - C:\Users\NaspeR\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2016-10-07]
CHR Extension: (Chrome Media Router) - C:\Users\NaspeR\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2016-10-25]
CHR Profile: C:\Users\NaspeR\AppData\Local\Google\Chrome\User Data\Profile 1 [2016-11-17]
CHR Extension: (Adblock Plus) - C:\Users\NaspeR\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\cfhdojbkjhnklbpkdaibdccddilifddb [2016-08-24]
CHR Extension: (Dokumenty Google offline) - C:\Users\NaspeR\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2016-07-29]
CHR Extension: (Platby Internetového obchodu Chrome) - C:\Users\NaspeR\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2016-07-29]
CHR Extension: (Gmail) - C:\Users\NaspeR\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2016-07-29]
CHR Extension: (Chrome Media Router) - C:\Users\NaspeR\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2016-10-07]
CHR HKU\S-1-5-21-2205024274-236154989-1138663683-1000\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [ccfifbojenkenpkmnbnndeadpfdiffof] - hxxps://clients2.google.com/service/update2/crx
CHR HKU\S-1-5-21-2205024274-236154989-1138663683-1000\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [oelpkepjlgmehajehfeicfbjdiobdkfj] - hxxps://clients2.google.com/service/update2/crx
CHR HKU\S-1-5-21-2205024274-236154989-1138663683-1000\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [ojlcebdkbpjdpiligkdbbkdkfjmchbfd] - hxxps://clients2.google.com/service/update2/crx
CHR HKLM-x32\...\Chrome\Extension: [daanglpcpkjjlkhcbladppjphglbigam] - hxxps://clients2.google.com/service/update2/crx
CHR HKLM-x32\...\Chrome\Extension: [eofcbnmajmjmplflapaojjnihcjkigck] - hxxps://clients2.google.com/service/update2/crx
CHR HKLM-x32\...\Chrome\Extension: [gomekmidlodglbbmalcneegieacbdmki] - hxxps://clients2.google.com/service/update2/crx
==================== Services (Whitelisted) ====================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R2 AtherosSvc; C:\Program Files (x86)\Bluetooth Suite\adminservice.exe [106144 2012-02-20] (Atheros Commnucations) [File not signed]
R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [197128 2016-09-09] (AVAST Software)
R2 Hamachi2Svc; C:\Program Files (x86)\LogMeIn Hamachi\x64\hamachi-2.exe [2627080 2016-11-11] (LogMeIn Inc.)
R2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [161560 2012-02-08] (Intel Corporation)
R2 LMIGuardianSvc; C:\Program Files (x86)\LogMeIn Hamachi\x64\LMIGuardianSvc.exe [419248 2016-11-11] (LogMeIn, Inc.)
S2 MBAMService; C:\Users\NaspeR\Desktop\Malwarebytes Anti-Malware Premium 2.2.1.1043 Final Portable (CZ)\App\Malwarebytes\mbamservice.exe [1136608 2016-11-22] (Malwarebytes)
R2 NvContainerLocalSystem; C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe [457152 2016-09-17] (NVIDIA Corporation)
S3 NvContainerNetworkService; C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe [457152 2016-09-17] (NVIDIA Corporation)
R2 NVIDIA Wireless Controller Service; C:\Program Files\NVIDIA Corporation\GeForce Experience Service\nvwirelesscontroller.exe [1163712 2016-09-17] (NVIDIA Corporation)
S3 TunngleService; C:\Program Files (x86)\Tunngle\TnglCtrl.exe [872432 2016-06-23] (Tunngle.net GmbH)
S3 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2009-07-14] (Microsoft Corporation)
R2 ZAtheros Wlan Agent; C:\Program Files (x86)\Atheros\Ath_WlanAgent.exe [72864 2012-02-19] (Atheros) [File not signed]
S4 MBAMScheduler; "\mbamscheduler.exe" [X]
S3 NBService; C:\Program Files (x86)\Nero\Nero 7\Nero BackItUp\NBService.exe [X]
S4 NMIndexingService; "C:\Program Files (x86)\Common Files\Ahead\Lib\NMIndexingService.exe" [X]
===================== Drivers (Whitelisted) ======================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
S3 aswHwid; C:\Windows\system32\drivers\aswHwid.sys [37656 2016-09-09] (AVAST Software)
R1 aswKbd; C:\Windows\system32\drivers\aswKbd.sys [37144 2016-09-09] (AVAST Software)
R2 aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [108816 2016-09-09] (AVAST Software)
R1 aswRdr; C:\Windows\system32\drivers\aswRdr2.sys [103064 2016-09-09] (AVAST Software)
R0 aswRvrt; C:\Windows\System32\Drivers\aswRvrt.sys [74544 2016-09-09] (AVAST Software)
R1 aswSnx; C:\Windows\system32\drivers\aswSnx.sys [969184 2016-09-13] (AVAST Software)
R1 aswSP; C:\Windows\system32\drivers\aswSP.sys [513632 2016-09-22] (AVAST Software)
S2 aswStm; C:\Windows\system32\drivers\aswStm.sys [163416 2016-09-09] (AVAST Software)
R0 aswVmm; C:\Windows\System32\Drivers\aswVmm.sys [293352 2016-10-13] (AVAST Software)
R1 dtsoftbus01; C:\Windows\System32\DRIVERS\dtsoftbus01.sys [283200 2016-06-26] (DT Soft Ltd)
R1 HWiNFO32; C:\Windows\SysWOW64\drivers\HWiNFO64A.SYS [26528 2016-07-14] (REALiX(tm))
R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [27008 2016-11-22] (Malwarebytes)
S3 MBAMWebAccessControl; C:\Windows\system32\drivers\mwac.sys [65408 2016-11-22] (Malwarebytes Corporation)
R3 MEIx64; C:\Windows\System32\DRIVERS\TeeDriverx64.sys [181304 2016-07-14] (Intel Corporation)
S3 NvStreamKms; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys [27584 2016-09-17] (NVIDIA Corporation)
R3 nvvad_WaveExtensible; C:\Windows\System32\drivers\nvvad64v.sys [46016 2016-09-17] (NVIDIA Corporation)
S3 semav6msr64; C:\Windows\system32\drivers\semav6msr64.sys [21984 2015-06-04] ()
R3 tap0901t; C:\Windows\System32\DRIVERS\tap0901t.sys [39464 2016-04-27] (Tunngle.net GmbH)
S3 wod0205; C:\Windows\System32\DRIVERS\wod0205.sys [33160 2011-04-23] (WeOnlyDo Software)
S3 Synth3dVsc; System32\drivers\synth3dvsc.sys [X]
S3 tsusbhub; system32\drivers\tsusbhub.sys [X]
S3 VGPU; System32\drivers\rdvgkmd.sys [X]
==================== NetSvcs (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
==================== One Month Created files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2016-11-22 16:34 - 2016-11-22 16:35 - 00019638 _____ C:\Users\NaspeR\Desktop\FRST.txt
2016-11-22 16:34 - 2016-11-22 16:34 - 00112640 _____ (forum.viry.cz) C:\Users\NaspeR\Desktop\FRSTLauncher.exe
2016-11-22 14:22 - 2016-11-22 14:23 - 00192216 _____ (Malwarebytes) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2016-11-22 14:22 - 2016-11-22 14:22 - 00000000 ____D C:\ProgramData\Malwarebytes
2016-11-22 13:56 - 2016-11-22 13:58 - 00201050 _____ C:\Users\NaspeR\Desktop\Addition.rar
2016-11-22 13:35 - 2016-11-22 16:34 - 00000000 ____D C:\FRST
2016-11-22 13:34 - 2016-11-22 13:34 - 02412544 _____ (Farbar) C:\Users\NaspeR\Desktop\FRST64.exe
2016-11-22 13:30 - 2016-11-22 14:22 - 00000000 ____D C:\Users\NaspeR\Desktop\Malwarebytes Anti-Malware Premium 2.2.1.1043 Final Portable (CZ)
2016-11-22 13:30 - 2016-11-22 13:30 - 00225355 _____ C:\Users\NaspeR\Desktop\dafgadfgadgadfg.dib
2016-11-22 08:16 - 2016-11-22 13:31 - 00140672 _____ (Malwarebytes) C:\Windows\system32\Drivers\mbamchameleon.sys
2016-11-22 08:16 - 2016-11-22 13:31 - 00065408 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys
2016-11-22 08:16 - 2016-11-22 13:31 - 00027008 _____ (Malwarebytes) C:\Windows\system32\Drivers\mbam.sys
2016-11-22 08:16 - 2016-11-22 08:16 - 00000000 ____D C:\ProgramData\Malwarebytes-BackupByMalwarebytesPortable
2016-11-21 12:33 - 2016-11-21 12:34 - 00000000 ____D C:\Users\NaspeR\Desktop\travian
2016-11-21 10:17 - 2016-11-22 08:31 - 00000924 _____ C:\Users\Public\Desktop\EPSON Scan.lnk
2016-11-21 10:17 - 2016-11-21 10:17 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\EPSON
2016-11-21 10:17 - 2016-11-21 10:17 - 00000000 ____D C:\Program Files (x86)\epson
2016-11-21 10:17 - 2012-07-24 00:00 - 00466432 _____ (Seiko Epson Corporation) C:\Windows\system32\esxw2ud.dll
2016-11-21 10:17 - 2009-10-16 00:00 - 00132560 _____ (Seiko Epson Corporation) C:\Windows\system32\esdevapp.exe
2016-11-21 10:17 - 2009-10-16 00:00 - 00013824 _____ (Seiko Epson Corporation) C:\Windows\system32\esxcdev.dll
2016-11-20 16:35 - 2016-11-22 07:24 - 00000000 ____D C:\ProgramData\AEM
2016-11-20 14:46 - 2016-11-20 14:46 - 00000558 _____ C:\Users\NaspeR\Desktop\CoD 2 – zástupce.lnk
2016-11-19 19:08 - 2016-11-22 08:31 - 00001112 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\4K YouTube to MP3.lnk
2016-11-19 19:08 - 2016-11-22 08:31 - 00001094 _____ C:\Users\Public\Desktop\4K YouTube to MP3.lnk
2016-11-19 19:08 - 2016-11-19 19:08 - 00000000 ____D C:\Program Files (x86)\4K YouTube to MP3
2016-11-17 15:15 - 2016-11-22 08:31 - 00000000 ____D C:\Users\NaspeR\Desktop\Nová složka (3)
2016-11-17 13:56 - 2016-11-17 13:56 - 00000000 ____D C:\ProgramData\ALI213
2016-11-17 09:26 - 2016-11-22 08:31 - 00000985 _____ C:\Users\Public\Desktop\Tunngle.lnk
2016-11-17 09:26 - 2016-11-17 09:26 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Tunngle
2016-11-17 09:25 - 2016-11-22 09:28 - 00000000 ____D C:\ProgramData\Tunngle
2016-11-17 09:25 - 2016-11-17 09:26 - 00000000 ____D C:\Program Files (x86)\Tunngle
2016-11-17 09:25 - 2016-11-17 09:25 - 00000000 ____D C:\Users\Public\Documents\Tunngle
2016-11-17 08:41 - 2016-11-17 08:44 - 00000000 ____D C:\Users\Default\AppData\Local\LogMeIn Hamachi
2016-11-17 08:41 - 2016-11-17 08:44 - 00000000 ____D C:\Users\Default User\AppData\Local\LogMeIn Hamachi
2016-11-17 08:41 - 2016-11-17 08:41 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\LogMeIn Hamachi
2016-11-17 08:41 - 2016-11-17 08:41 - 00000000 ____D C:\Program Files (x86)\LogMeIn Hamachi
2016-11-17 08:41 - 2016-11-11 13:47 - 00034720 ____H (LogMeIn, Inc.) C:\Windows\system32\hamachi.sys
2016-11-16 21:03 - 2016-11-16 21:04 - 00000000 ____D C:\Users\NaspeR\Desktop\jackass
2016-11-16 16:59 - 2016-11-16 16:59 - 01065376 _____ (Google Inc.) C:\Users\NaspeR\Desktop\ChromeSetup.exe
2016-11-14 12:19 - 2016-11-14 12:20 - 00000947 _____ C:\Users\NaspeR\Desktop\RelicCOH – zástupce.lnk
2016-11-12 11:54 - 2016-11-12 11:54 - 00000000 ____D C:\Users\NaspeR\AppData\LocalLow\KMPlayer
2016-11-11 09:41 - 2016-11-22 14:40 - 00000000 __SHD C:\ProgramData\JSCPXA
2016-11-10 09:08 - 2016-04-27 00:49 - 00039464 _____ (Tunngle.net GmbH) C:\Windows\system32\Drivers\tap0901t.sys
2016-11-09 12:43 - 2016-11-12 11:40 - 00000000 ____D C:\ProgramData\Media Center Programs
2016-11-09 12:34 - 2007-03-15 16:57 - 00443752 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx10_33.dll
2016-11-09 12:34 - 2007-03-12 16:42 - 03495784 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx9_33.dll
2016-11-09 12:34 - 2007-03-12 16:42 - 01123696 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DCompiler_33.dll
2016-11-09 12:34 - 2006-03-31 12:40 - 02388176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx9_30.dll
2016-11-09 12:31 - 2016-11-09 12:31 - 00000000 __SHD C:\Windows\ftpcache
2016-11-07 12:41 - 2016-11-07 12:41 - 00000000 ____D C:\Users\NaspeR\AppData\Roaming\GHISLER
2016-11-05 09:02 - 2016-11-05 09:02 - 00000000 ____D C:\Users\NaspeR\Documents\My Cheat Tables
2016-11-03 14:45 - 2016-11-22 08:31 - 00001171 _____ C:\Users\NaspeR\Desktop\Lightshot.lnk
2016-11-03 14:45 - 2016-11-03 14:45 - 00000000 ____D C:\Users\NaspeR\Documents\Lightshot
2016-11-03 09:21 - 2016-11-03 09:21 - 00000000 ____H C:\Windows\system32\Drivers\Msft_Kernel_btath_hcrp_01009.Wdf
2016-11-03 07:25 - 2016-11-22 16:28 - 00000390 _____ C:\Windows\Tasks\update-sys.job
2016-11-03 07:25 - 2016-11-22 15:31 - 00000390 _____ C:\Windows\Tasks\update-S-1-5-21-2205024274-236154989-1138663683-1000.job
2016-11-03 07:25 - 2016-11-03 07:25 - 00003286 _____ C:\Windows\System32\Tasks\update-sys
2016-11-03 07:25 - 2016-11-03 07:25 - 00003266 _____ C:\Windows\System32\Tasks\update-S-1-5-21-2205024274-236154989-1138663683-1000
2016-11-03 07:25 - 2016-11-03 07:25 - 00000424 _____ C:\Users\NaspeR\AppData\Local\UserProducts.xml
2016-11-03 07:25 - 2016-11-03 07:25 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Lightshot
2016-11-03 07:25 - 2016-11-03 07:25 - 00000000 ____D C:\Program Files (x86)\Skillbrains
2016-11-01 13:57 - 2016-11-01 13:57 - 00002794 _____ C:\Windows\System32\Tasks\CCleanerSkipUAC
2016-11-01 13:43 - 2016-11-01 13:43 - 00000000 ____D C:\Users\NaspeR\AppData\Local\Steam
2016-10-31 12:22 - 2016-11-22 14:42 - 00000000 ____D C:\Users\NaspeR\AppData\Local\LogMeIn Hamachi
2016-10-31 12:20 - 2016-11-22 08:31 - 00000920 _____ C:\Users\Public\Desktop\LogMeIn Hamachi.lnk
Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 20-11-2016 01
Ran by NaspeR (administrator) on NASPER-PC (22-11-2016 16:34:53)
Running from C:\Users\NaspeR\Desktop
Loaded Profiles: NaspeR (Available Profiles: NaspeR)
Platform: Windows 7 Ultimate Service Pack 1 (X64) Language: Angličtina (Spojené státy)
Internet Explorer Version 8 (Default browser: Chrome)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/33 ... scan-tool/
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
(Microsoft Corporation) C:\Windows\System32\wlanext.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe
(Atheros Commnucations) C:\Program Files (x86)\Bluetooth Suite\AdminService.exe
(Node.js) C:\Program Files (x86)\NVIDIA Corporation\NvNode\NVIDIA Web Helper.exe
(Dritek System Inc.) C:\Program Files (x86)\Launch Manager\dsiwmis.exe
(Intel(R) Corporation) C:\Program Files\Intel\iCLS Client\HeciServer.exe
(Dritek System Inc.) C:\Program Files (x86)\Launch Manager\LMworker.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\Jhi_service.exe
(LogMeIn, Inc.) C:\Program Files (x86)\LogMeIn Hamachi\x64\LMIGuardianSvc.exe
(Dritek System Inc.) C:\Program Files (x86)\Launch Manager\LMutilps32.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\GeForce Experience Service\nvwirelesscontroller.exe
(Atheros) C:\Program Files (x86)\Atheros\Ath_WlanAgent.exe
(LogMeIn Inc.) C:\Program Files (x86)\LogMeIn Hamachi\x64\hamachi-2.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NvContainer\nvcontainer.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(Intel Corporation) C:\Windows\System32\igfxpers.exe
(ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDCtrl.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
(ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDCtrlHelper.exe
(Dritek System Inc.) C:\Program Files (x86)\Launch Manager\LManager.exe
(Piriform Ltd) C:\Program Files\CCleaner\CCleaner64.exe
(Dolby Laboratories Inc.) C:\Dolby PCEE4\pcee4.exe
(Dritek System Inc.) C:\Program Files (x86)\Launch Manager\MMDx64Fx.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\avastui.exe
(Intel Corporation) C:\Windows\System32\igfxext.exe
(Intel Corporation) C:\Windows\System32\igfxsrvc.exe
(Skillbrains) C:\Program Files (x86)\Skillbrains\lightshot\5.4.0.1\Lightshot.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Skype Technologies S.A.) C:\Program Files (x86)\Skype\Phone\Skype.exe
(PandoraTV) C:\KMPlayer\KMPlayer.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(forum.viry.cz) C:\Users\NaspeR\Desktop\FRSTLauncher.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
==================== Registry (Whitelisted) ====================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [ETDCtrl] => C:\Program Files\Elantech\ETDCtrl.exe [2821936 2012-03-07] (ELAN Microelectronics Corp.)
HKLM\...\Run: [RtHDVCpl] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [12343400 2011-12-27] (Realtek Semiconductor)
HKLM\...\Run: [RtHDVBg_Dolby] => C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [1156712 2011-11-15] (Realtek Semiconductor)
HKLM\...\Run: [IntelTBRunOnce] => wscript.exe //b //nologo "C:\Program Files\Intel\TurboBoost\RunTBGadgetOnce.vbs"
HKLM\...\Run: [ShadowPlay] => "C:\Windows\system32\rundll32.exe" C:\Windows\system32\nvspcap64.dll,ShadowPlayOnSystemStart
HKLM-x32\...\Run: [IAStorIcon] => C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [284440 2012-02-01] (Intel Corporation)
HKLM-x32\...\Run: [LManager] => C:\Program Files (x86)\Launch Manager\LManager.exe [1105488 2012-03-23] (Dritek System Inc.)
HKLM-x32\...\Run: [Dolby Home Theater v4] => C:\Dolby PCEE4\pcee4.exe [506712 2011-06-01] (Dolby Laboratories Inc.)
HKLM-x32\...\Run: [AvastUI.exe] => C:\Program Files\AVAST Software\Avast\AvastUI.exe [9080768 2016-11-15] (AVAST Software)
HKLM-x32\...\Run: [GrooveMonitor] => C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe [31016 2006-10-26] (Microsoft Corporation)
HKLM-x32\...\Run: [Lightshot] => C:\Program Files (x86)\Skillbrains\lightshot\Lightshot.exe [225944 2016-07-11] ()
HKLM-x32\...\Run: [LogMeIn Hamachi Ui] => C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe [5565960 2016-11-11] (LogMeIn Inc.)
Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation)
HKU\S-1-5-21-2205024274-236154989-1138663683-1000\...\Run: [DAEMON Tools Lite] => C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe [3673728 2012-11-06] (DT Soft Ltd)
HKU\S-1-5-21-2205024274-236154989-1138663683-1000\...\Run: [CCleaner Monitoring] => C:\Program Files\CCleaner\CCleaner64.exe [8641240 2016-02-12] (Piriform Ltd)
HKU\S-1-5-21-2205024274-236154989-1138663683-1000\...\Run: [UFX Start] => C:\ProgramData\JSCPXA\UFX.exe
HKU\S-1-5-21-2205024274-236154989-1138663683-1000\...\MountPoints2: {2dbd70c9-3b93-11e6-9c5b-806e6f6e6963} - E:\AutoRun\AutoRunX\AutoRunX.exe
HKU\S-1-5-21-2205024274-236154989-1138663683-1000\...\MountPoints2: {a9000636-3b8f-11e6-afc0-806e6f6e6963} - E:\AutoRun\AutoRunX\AutoRunX.exe
HKU\S-1-5-18\...\RunOnce: [SPReview] => C:\Windows\System32\SPReview\SPReview.exe [301568 2016-10-31] (Microsoft Corporation)
AppInit_DLLs: C:\Windows\system32\nvinitx.dll => C:\Windows\system32\nvinitx.dll [177952 2016-07-11] (NVIDIA Corporation)
AppInit_DLLs-x32: C:\Windows\SysWOW64\nvinit.dll => C:\Windows\SysWOW64\nvinit.dll [155768 2016-07-11] (NVIDIA Corporation)
ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShA64.dll [2016-09-09] (AVAST Software)
GroupPolicy: Restriction <======= ATTENTION
GroupPolicy\User: Restriction <======= ATTENTION
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
Tcpip\Parameters: [DhcpNameServer] 10.10.10.1
Tcpip\..\Interfaces\{248A6460-987F-42C5-AAF7-C0AD5C75696C}: [DhcpNameServer] 7.254.254.254
Tcpip\..\Interfaces\{2F34CD87-E306-46CA-8C62-A2A533E840FB}: [DhcpNameServer] 10.10.10.1
Tcpip\..\Interfaces\{E04FD461-BE03-45D2-8C7A-886F0F91A499}: [DhcpNameServer] 10.10.10.1
ManualProxies:
Internet Explorer:
==================
HKU\S-1-5-21-2205024274-236154989-1138663683-1000\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
SearchScopes: HKU\S-1-5-21-2205024274-236154989-1138663683-1000 -> DefaultScope {FFEBBF0A-C22C-4172-89FF-45215A135AC7} URL = hxxp://go.mail.ru/distib/ep/?q={SearchTerms}&product_id=%7BC7F9878F-D1CC-4142-881C-47164E52D35D%7D&gp=811014
SearchScopes: HKU\S-1-5-21-2205024274-236154989-1138663683-1000 -> {FFEBBF0A-C22C-4172-89FF-45215A135AC7} URL = hxxp://go.mail.ru/distib/ep/?q={SearchTerms}&product_id=%7BC7F9878F-D1CC-4142-881C-47164E52D35D%7D&gp=811014
BHO: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll [2016-10-24] (AVAST Software)
BHO-x32: CIESpeechBHO Class -> {8D10F6C4-0E01-4BD4-8601-11AC1FDF8126} -> C:\Program Files (x86)\Bluetooth Suite\IEPlugIn.dll [2012-02-20] (Atheros Commnucations)
BHO-x32: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll [2016-10-24] (AVAST Software)
Filter: deflate - {8f6b0360-b80d-11d0-a9b3-006097942311} - C:\Windows\system32\urlmon.dll [2010-11-20] (Microsoft Corporation)
Filter-x32: deflate - {8f6b0360-b80d-11d0-a9b3-006097942311} - C:\Windows\SysWOW64\urlmon.dll [2010-11-20] (Microsoft Corporation)
Filter: gzip - {8f6b0360-b80d-11d0-a9b3-006097942311} - C:\Windows\system32\urlmon.dll [2010-11-20] (Microsoft Corporation)
Filter-x32: gzip - {8f6b0360-b80d-11d0-a9b3-006097942311} - C:\Windows\SysWOW64\urlmon.dll [2010-11-20] (Microsoft Corporation)
FireFox:
========
FF HKLM\...\Firefox\Extensions: [wrc@avast.com] - C:\Program Files\AVAST Software\Avast\WebRep\FF
FF Extension: (Avast Online Security) - C:\Program Files\AVAST Software\Avast\WebRep\FF [2016-09-09]
FF HKLM\...\Firefox\Extensions: [sp@avast.com] - C:\Program Files\AVAST Software\Avast\SafePrice\FF
FF Extension: (Avast SafePrice) - C:\Program Files\AVAST Software\Avast\SafePrice\FF [2016-09-09]
FF HKLM-x32\...\Firefox\Extensions: [wrc@avast.com] - C:\Program Files\AVAST Software\Avast\WebRep\FF
FF HKLM-x32\...\Firefox\Extensions: [sp@avast.com] - C:\Program Files\AVAST Software\Avast\SafePrice\FF
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=2.0.59 -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll [2012-01-06] (Intel Corporation)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll [2012-01-06] (Intel Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.31.5\npGoogleUpdate3.dll [2016-10-07] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.31.5\npGoogleUpdate3.dll [2016-10-07] (Google Inc.)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll [2016-06-30] (Adobe Systems Inc.)
Chrome:
=======
CHR DefaultProfile: Default
CHR HomePage: Default -> mail.ru/cnt/11956636?rciguc__PARAM__
CHR StartupUrls: Default -> "hxxps://www.google.cz/"
CHR DefaultSearchURL: Default -> hxxps://inline.go.mail.ru/search?inline_comp=dse&q={searchTerms}&fr=chxtn12.0.11
CHR DefaultSearchKeyword: Default -> mail.ru
CHR DefaultSuggestURL: Default -> hxxp://suggests.go.mail.ru/chrome?q={searchTerms}
CHR Profile: C:\Users\NaspeR\AppData\Local\Google\Chrome\User Data\Default [2016-11-22]
CHR Extension: (Prezentace Google) - C:\Users\NaspeR\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2016-10-07]
CHR Extension: (Dokumenty Google) - C:\Users\NaspeR\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2016-10-07]
CHR Extension: (Disk Google) - C:\Users\NaspeR\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2016-10-07]
CHR Extension: (App Launcher for Messenger) - C:\Users\NaspeR\AppData\Local\Google\Chrome\User Data\Default\Extensions\bllmngcdibgbgjnginpehneeofhbmdjm [2016-10-28]
CHR Extension: (YouTube) - C:\Users\NaspeR\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2016-10-07]
CHR Extension: (Adblock Plus) - C:\Users\NaspeR\AppData\Local\Google\Chrome\User Data\Default\Extensions\cfhdojbkjhnklbpkdaibdccddilifddb [2016-10-26]
CHR Extension: (Tabulky Google) - C:\Users\NaspeR\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2016-10-07]
CHR Extension: (Dokumenty Google offline) - C:\Users\NaspeR\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2016-10-07]
CHR Extension: (Platby Internetového obchodu Chrome) - C:\Users\NaspeR\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2016-10-07]
CHR Extension: (Gmail) - C:\Users\NaspeR\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2016-10-07]
CHR Extension: (Chrome Media Router) - C:\Users\NaspeR\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2016-10-25]
CHR Profile: C:\Users\NaspeR\AppData\Local\Google\Chrome\User Data\Profile 1 [2016-11-17]
CHR Extension: (Adblock Plus) - C:\Users\NaspeR\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\cfhdojbkjhnklbpkdaibdccddilifddb [2016-08-24]
CHR Extension: (Dokumenty Google offline) - C:\Users\NaspeR\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2016-07-29]
CHR Extension: (Platby Internetového obchodu Chrome) - C:\Users\NaspeR\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2016-07-29]
CHR Extension: (Gmail) - C:\Users\NaspeR\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2016-07-29]
CHR Extension: (Chrome Media Router) - C:\Users\NaspeR\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2016-10-07]
CHR HKU\S-1-5-21-2205024274-236154989-1138663683-1000\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [ccfifbojenkenpkmnbnndeadpfdiffof] - hxxps://clients2.google.com/service/update2/crx
CHR HKU\S-1-5-21-2205024274-236154989-1138663683-1000\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [oelpkepjlgmehajehfeicfbjdiobdkfj] - hxxps://clients2.google.com/service/update2/crx
CHR HKU\S-1-5-21-2205024274-236154989-1138663683-1000\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [ojlcebdkbpjdpiligkdbbkdkfjmchbfd] - hxxps://clients2.google.com/service/update2/crx
CHR HKLM-x32\...\Chrome\Extension: [daanglpcpkjjlkhcbladppjphglbigam] - hxxps://clients2.google.com/service/update2/crx
CHR HKLM-x32\...\Chrome\Extension: [eofcbnmajmjmplflapaojjnihcjkigck] - hxxps://clients2.google.com/service/update2/crx
CHR HKLM-x32\...\Chrome\Extension: [gomekmidlodglbbmalcneegieacbdmki] - hxxps://clients2.google.com/service/update2/crx
==================== Services (Whitelisted) ====================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R2 AtherosSvc; C:\Program Files (x86)\Bluetooth Suite\adminservice.exe [106144 2012-02-20] (Atheros Commnucations) [File not signed]
R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [197128 2016-09-09] (AVAST Software)
R2 Hamachi2Svc; C:\Program Files (x86)\LogMeIn Hamachi\x64\hamachi-2.exe [2627080 2016-11-11] (LogMeIn Inc.)
R2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [161560 2012-02-08] (Intel Corporation)
R2 LMIGuardianSvc; C:\Program Files (x86)\LogMeIn Hamachi\x64\LMIGuardianSvc.exe [419248 2016-11-11] (LogMeIn, Inc.)
S2 MBAMService; C:\Users\NaspeR\Desktop\Malwarebytes Anti-Malware Premium 2.2.1.1043 Final Portable (CZ)\App\Malwarebytes\mbamservice.exe [1136608 2016-11-22] (Malwarebytes)
R2 NvContainerLocalSystem; C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe [457152 2016-09-17] (NVIDIA Corporation)
S3 NvContainerNetworkService; C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe [457152 2016-09-17] (NVIDIA Corporation)
R2 NVIDIA Wireless Controller Service; C:\Program Files\NVIDIA Corporation\GeForce Experience Service\nvwirelesscontroller.exe [1163712 2016-09-17] (NVIDIA Corporation)
S3 TunngleService; C:\Program Files (x86)\Tunngle\TnglCtrl.exe [872432 2016-06-23] (Tunngle.net GmbH)
S3 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2009-07-14] (Microsoft Corporation)
R2 ZAtheros Wlan Agent; C:\Program Files (x86)\Atheros\Ath_WlanAgent.exe [72864 2012-02-19] (Atheros) [File not signed]
S4 MBAMScheduler; "\mbamscheduler.exe" [X]
S3 NBService; C:\Program Files (x86)\Nero\Nero 7\Nero BackItUp\NBService.exe [X]
S4 NMIndexingService; "C:\Program Files (x86)\Common Files\Ahead\Lib\NMIndexingService.exe" [X]
===================== Drivers (Whitelisted) ======================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
S3 aswHwid; C:\Windows\system32\drivers\aswHwid.sys [37656 2016-09-09] (AVAST Software)
R1 aswKbd; C:\Windows\system32\drivers\aswKbd.sys [37144 2016-09-09] (AVAST Software)
R2 aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [108816 2016-09-09] (AVAST Software)
R1 aswRdr; C:\Windows\system32\drivers\aswRdr2.sys [103064 2016-09-09] (AVAST Software)
R0 aswRvrt; C:\Windows\System32\Drivers\aswRvrt.sys [74544 2016-09-09] (AVAST Software)
R1 aswSnx; C:\Windows\system32\drivers\aswSnx.sys [969184 2016-09-13] (AVAST Software)
R1 aswSP; C:\Windows\system32\drivers\aswSP.sys [513632 2016-09-22] (AVAST Software)
S2 aswStm; C:\Windows\system32\drivers\aswStm.sys [163416 2016-09-09] (AVAST Software)
R0 aswVmm; C:\Windows\System32\Drivers\aswVmm.sys [293352 2016-10-13] (AVAST Software)
R1 dtsoftbus01; C:\Windows\System32\DRIVERS\dtsoftbus01.sys [283200 2016-06-26] (DT Soft Ltd)
R1 HWiNFO32; C:\Windows\SysWOW64\drivers\HWiNFO64A.SYS [26528 2016-07-14] (REALiX(tm))
R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [27008 2016-11-22] (Malwarebytes)
S3 MBAMWebAccessControl; C:\Windows\system32\drivers\mwac.sys [65408 2016-11-22] (Malwarebytes Corporation)
R3 MEIx64; C:\Windows\System32\DRIVERS\TeeDriverx64.sys [181304 2016-07-14] (Intel Corporation)
S3 NvStreamKms; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys [27584 2016-09-17] (NVIDIA Corporation)
R3 nvvad_WaveExtensible; C:\Windows\System32\drivers\nvvad64v.sys [46016 2016-09-17] (NVIDIA Corporation)
S3 semav6msr64; C:\Windows\system32\drivers\semav6msr64.sys [21984 2015-06-04] ()
R3 tap0901t; C:\Windows\System32\DRIVERS\tap0901t.sys [39464 2016-04-27] (Tunngle.net GmbH)
S3 wod0205; C:\Windows\System32\DRIVERS\wod0205.sys [33160 2011-04-23] (WeOnlyDo Software)
S3 Synth3dVsc; System32\drivers\synth3dvsc.sys [X]
S3 tsusbhub; system32\drivers\tsusbhub.sys [X]
S3 VGPU; System32\drivers\rdvgkmd.sys [X]
==================== NetSvcs (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
==================== One Month Created files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2016-11-22 16:34 - 2016-11-22 16:35 - 00019638 _____ C:\Users\NaspeR\Desktop\FRST.txt
2016-11-22 16:34 - 2016-11-22 16:34 - 00112640 _____ (forum.viry.cz) C:\Users\NaspeR\Desktop\FRSTLauncher.exe
2016-11-22 14:22 - 2016-11-22 14:23 - 00192216 _____ (Malwarebytes) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2016-11-22 14:22 - 2016-11-22 14:22 - 00000000 ____D C:\ProgramData\Malwarebytes
2016-11-22 13:56 - 2016-11-22 13:58 - 00201050 _____ C:\Users\NaspeR\Desktop\Addition.rar
2016-11-22 13:35 - 2016-11-22 16:34 - 00000000 ____D C:\FRST
2016-11-22 13:34 - 2016-11-22 13:34 - 02412544 _____ (Farbar) C:\Users\NaspeR\Desktop\FRST64.exe
2016-11-22 13:30 - 2016-11-22 14:22 - 00000000 ____D C:\Users\NaspeR\Desktop\Malwarebytes Anti-Malware Premium 2.2.1.1043 Final Portable (CZ)
2016-11-22 13:30 - 2016-11-22 13:30 - 00225355 _____ C:\Users\NaspeR\Desktop\dafgadfgadgadfg.dib
2016-11-22 08:16 - 2016-11-22 13:31 - 00140672 _____ (Malwarebytes) C:\Windows\system32\Drivers\mbamchameleon.sys
2016-11-22 08:16 - 2016-11-22 13:31 - 00065408 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys
2016-11-22 08:16 - 2016-11-22 13:31 - 00027008 _____ (Malwarebytes) C:\Windows\system32\Drivers\mbam.sys
2016-11-22 08:16 - 2016-11-22 08:16 - 00000000 ____D C:\ProgramData\Malwarebytes-BackupByMalwarebytesPortable
2016-11-21 12:33 - 2016-11-21 12:34 - 00000000 ____D C:\Users\NaspeR\Desktop\travian
2016-11-21 10:17 - 2016-11-22 08:31 - 00000924 _____ C:\Users\Public\Desktop\EPSON Scan.lnk
2016-11-21 10:17 - 2016-11-21 10:17 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\EPSON
2016-11-21 10:17 - 2016-11-21 10:17 - 00000000 ____D C:\Program Files (x86)\epson
2016-11-21 10:17 - 2012-07-24 00:00 - 00466432 _____ (Seiko Epson Corporation) C:\Windows\system32\esxw2ud.dll
2016-11-21 10:17 - 2009-10-16 00:00 - 00132560 _____ (Seiko Epson Corporation) C:\Windows\system32\esdevapp.exe
2016-11-21 10:17 - 2009-10-16 00:00 - 00013824 _____ (Seiko Epson Corporation) C:\Windows\system32\esxcdev.dll
2016-11-20 16:35 - 2016-11-22 07:24 - 00000000 ____D C:\ProgramData\AEM
2016-11-20 14:46 - 2016-11-20 14:46 - 00000558 _____ C:\Users\NaspeR\Desktop\CoD 2 – zástupce.lnk
2016-11-19 19:08 - 2016-11-22 08:31 - 00001112 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\4K YouTube to MP3.lnk
2016-11-19 19:08 - 2016-11-22 08:31 - 00001094 _____ C:\Users\Public\Desktop\4K YouTube to MP3.lnk
2016-11-19 19:08 - 2016-11-19 19:08 - 00000000 ____D C:\Program Files (x86)\4K YouTube to MP3
2016-11-17 15:15 - 2016-11-22 08:31 - 00000000 ____D C:\Users\NaspeR\Desktop\Nová složka (3)
2016-11-17 13:56 - 2016-11-17 13:56 - 00000000 ____D C:\ProgramData\ALI213
2016-11-17 09:26 - 2016-11-22 08:31 - 00000985 _____ C:\Users\Public\Desktop\Tunngle.lnk
2016-11-17 09:26 - 2016-11-17 09:26 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Tunngle
2016-11-17 09:25 - 2016-11-22 09:28 - 00000000 ____D C:\ProgramData\Tunngle
2016-11-17 09:25 - 2016-11-17 09:26 - 00000000 ____D C:\Program Files (x86)\Tunngle
2016-11-17 09:25 - 2016-11-17 09:25 - 00000000 ____D C:\Users\Public\Documents\Tunngle
2016-11-17 08:41 - 2016-11-17 08:44 - 00000000 ____D C:\Users\Default\AppData\Local\LogMeIn Hamachi
2016-11-17 08:41 - 2016-11-17 08:44 - 00000000 ____D C:\Users\Default User\AppData\Local\LogMeIn Hamachi
2016-11-17 08:41 - 2016-11-17 08:41 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\LogMeIn Hamachi
2016-11-17 08:41 - 2016-11-17 08:41 - 00000000 ____D C:\Program Files (x86)\LogMeIn Hamachi
2016-11-17 08:41 - 2016-11-11 13:47 - 00034720 ____H (LogMeIn, Inc.) C:\Windows\system32\hamachi.sys
2016-11-16 21:03 - 2016-11-16 21:04 - 00000000 ____D C:\Users\NaspeR\Desktop\jackass
2016-11-16 16:59 - 2016-11-16 16:59 - 01065376 _____ (Google Inc.) C:\Users\NaspeR\Desktop\ChromeSetup.exe
2016-11-14 12:19 - 2016-11-14 12:20 - 00000947 _____ C:\Users\NaspeR\Desktop\RelicCOH – zástupce.lnk
2016-11-12 11:54 - 2016-11-12 11:54 - 00000000 ____D C:\Users\NaspeR\AppData\LocalLow\KMPlayer
2016-11-11 09:41 - 2016-11-22 14:40 - 00000000 __SHD C:\ProgramData\JSCPXA
2016-11-10 09:08 - 2016-04-27 00:49 - 00039464 _____ (Tunngle.net GmbH) C:\Windows\system32\Drivers\tap0901t.sys
2016-11-09 12:43 - 2016-11-12 11:40 - 00000000 ____D C:\ProgramData\Media Center Programs
2016-11-09 12:34 - 2007-03-15 16:57 - 00443752 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx10_33.dll
2016-11-09 12:34 - 2007-03-12 16:42 - 03495784 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx9_33.dll
2016-11-09 12:34 - 2007-03-12 16:42 - 01123696 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DCompiler_33.dll
2016-11-09 12:34 - 2006-03-31 12:40 - 02388176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx9_30.dll
2016-11-09 12:31 - 2016-11-09 12:31 - 00000000 __SHD C:\Windows\ftpcache
2016-11-07 12:41 - 2016-11-07 12:41 - 00000000 ____D C:\Users\NaspeR\AppData\Roaming\GHISLER
2016-11-05 09:02 - 2016-11-05 09:02 - 00000000 ____D C:\Users\NaspeR\Documents\My Cheat Tables
2016-11-03 14:45 - 2016-11-22 08:31 - 00001171 _____ C:\Users\NaspeR\Desktop\Lightshot.lnk
2016-11-03 14:45 - 2016-11-03 14:45 - 00000000 ____D C:\Users\NaspeR\Documents\Lightshot
2016-11-03 09:21 - 2016-11-03 09:21 - 00000000 ____H C:\Windows\system32\Drivers\Msft_Kernel_btath_hcrp_01009.Wdf
2016-11-03 07:25 - 2016-11-22 16:28 - 00000390 _____ C:\Windows\Tasks\update-sys.job
2016-11-03 07:25 - 2016-11-22 15:31 - 00000390 _____ C:\Windows\Tasks\update-S-1-5-21-2205024274-236154989-1138663683-1000.job
2016-11-03 07:25 - 2016-11-03 07:25 - 00003286 _____ C:\Windows\System32\Tasks\update-sys
2016-11-03 07:25 - 2016-11-03 07:25 - 00003266 _____ C:\Windows\System32\Tasks\update-S-1-5-21-2205024274-236154989-1138663683-1000
2016-11-03 07:25 - 2016-11-03 07:25 - 00000424 _____ C:\Users\NaspeR\AppData\Local\UserProducts.xml
2016-11-03 07:25 - 2016-11-03 07:25 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Lightshot
2016-11-03 07:25 - 2016-11-03 07:25 - 00000000 ____D C:\Program Files (x86)\Skillbrains
2016-11-01 13:57 - 2016-11-01 13:57 - 00002794 _____ C:\Windows\System32\Tasks\CCleanerSkipUAC
2016-11-01 13:43 - 2016-11-01 13:43 - 00000000 ____D C:\Users\NaspeR\AppData\Local\Steam
2016-10-31 12:22 - 2016-11-22 14:42 - 00000000 ____D C:\Users\NaspeR\AppData\Local\LogMeIn Hamachi
2016-10-31 12:20 - 2016-11-22 08:31 - 00000920 _____ C:\Users\Public\Desktop\LogMeIn Hamachi.lnk